Uploaded image for project: 'Sentry (Retired)'
  1. Sentry (Retired)
  2. SENTRY-2533

The UDF in_file should be blacked default

    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.1.0
    • 2.2.0
    • Sentry

    Description

      HIVE-20420(CVE-2018-11777) introduced a fallback authorizer factory which disallowed some builtin UDFs such as java_method, reflect, reflect2 and in_file. But Sentry does not black in_file up to now, so a malicious user can use in_file in SQL queries to detect some specific files on the HS2 host, or to detect whether a specific file has specific content. in_file should be added to HIVE_UDF_BLACK_LIST.

      Attachments

        1. SENTRY-2533.001.patch
          3 kB
          Wenchao Li
        2. SENTRY-2533.001.patch
          3 kB
          Wenchao Li
        3. SENTRY-2533.001.patch
          3 kB
          Wenchao Li
        4. SENTRY-2533.001.patch
          3 kB
          Wenchao Li

        Issue Links

          Activity

            People

              1wc Wenchao Li
              1wc Wenchao Li
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: