In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/bid/98961 | Third Party Advisory VDB Entry | 
| https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger | Release Notes Vendor Advisory | 
| http://www.securityfocus.com/bid/98961 | Third Party Advisory VDB Entry | 
| https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger | Release Notes Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 03:32
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.securityfocus.com/bid/98961 - Third Party Advisory, VDB Entry | |
| References | () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - Release Notes, Vendor Advisory | 
Information
                Published : 2017-06-14 17:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-7677
Mitre link : CVE-2017-7677
CVE.ORG link : CVE-2017-7677
JSON object : View
Products Affected
                apache
- ranger
 
CWE
                
                    
                        
                        CWE-862
                        
            Missing Authorization
