CVE-2024-29869

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 28, 2025
Updated: Jan 29, 2025
CWE ID 732

Summary

CVE-2024-29869 is a vulnerability affecting Hive software. When users don't set explicit file permissions, Hive generates a credentials file to a temporary directory with default permissions of 644. This permits unauthorized users with access to the directory to read the sensitive information contained within the file. It is strongly advised that users upgrade to version 4.0.1 to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apache Hive

Affected Vendors

  • Apache Software Foundation