CVE detail
CVE-2024-29869 — CVE-2024-29869
Published 2025-01-28 · Modified 2026-06-17 · Vendor apache · Product hive · Source nvd
MEDIUM
severity
CVSS-derived band
0.0027
EPSS probability
exploitation probability, 30d
20.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version 4.0.1, which fixes this issue.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References