Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-37266

View text can only be SELECT queries

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.3.0
    • 3.3.0
    • SQL
    • None

    Description

      The current implementation of persistent view is create hive table with view text.
      The view text is just a query string, so the hackers may tamper with it through various means.
      Such as:

      select * from tab1
      

      tampered with

      drop table tab1
      

      Attachments

        Activity

          People

            beliefer Jiaan Geng
            beliefer Jiaan Geng
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: