StackRadar

CVE-2024-23953

Medium

Advisory

Published 28 Jan 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by Spoofing

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
hive-llap-commonmaven2.3.2, 2.3.4, 2.3.9, 2.3.9-dremio-202305101625150255-0beca91+1 more4.0.010
OSV records
GHSA-p953-3j66-hg45

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
hive-llap-common@3.1.3
4.0.0

Open the chart page →

7,166
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
hive-llap-common@2.3.2
4.0.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
hive-llap-common@2.3.2
4.0.0

Open the chart page →

20,837
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
hive-llap-common@3.1.3
4.0.0

Open the chart page →

7,335
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
hive-llap-common@2.3.9
4.0.0

Open the chart page →

8,198
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
hive-llap-common@3.1.3
4.0.0

Open the chart page →

7,740
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
hive-llap-common@2.3.2
4.0.0

Open the chart page →

6,882
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
hive-llap-common@2.3.4
4.0.0

Open the chart page →

6,165
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
hive-llap-common@2.3.9
4.0.0

Open the chart page →

7,835
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
hive-llap-common@2.3.2
4.0.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
hive-llap-common@2.3.2
4.0.0

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
hive-llap-common@2.3.2
4.0.0

Open the chart page →

6,882
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
hive-llap-common@2.3.9-dremio-202305101625150255-0beca91
4.0.0

Open the chart page →

37,671
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2024-23953.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
hive-llap-common@3.1.3
4.0.0

Open the chart page →

9,397

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
hive-llap-common@2.3.2
4.0.0
4
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
hive-llap-common@2.3.2
4.0.0
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
hive-llap-common@3.1.3
4.0.0
1
apache/drill:1.21.11f96558fd292
hive-llap-common@3.1.3
4.0.0
1
apache/ranger:2.7.076c176e8a0e4
hive-llap-common@3.1.3
4.0.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
hive-llap-common@2.3.9-dremio-202305101625150255-0beca91
4.0.0
1
library/storm:2.4.0bd5d420506d6
hive-llap-common@2.3.4
4.0.0
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
hive-llap-common@2.3.9
4.0.0
1
sslhep/hive-metastore:3.1.39e80af083079
hive-llap-common@3.1.3
4.0.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
hive-llap-common@2.3.9
4.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.