-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the use of Arrays.equals() in the checkSignature method of LlapSignerImpl. The commit diff explicitly shows the replacement of Arrays.equals() with MessageDigest.isEqual(), a constant-time comparison method. The CVE description and GHSA advisory directly attribute the vulnerability to this non-constant-time comparison. The file path and method name match the code change in the provided commit, confirming the location of the vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.hive:hive-llap-common | maven | < 4.0.0 | 4.0.0 |
Ongoing coverage of React2Shell