[ https://issues.apache.org/jira/browse/SENTRY-960?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Ryan P reassigned SENTRY-960: ----------------------------- Assignee: Ryan P > Sentry no longer enforces it's whitelist > ---------------------------------------- > > Key: SENTRY-960 > URL: https://issues.apache.org/jira/browse/SENTRY-960 > Project: Sentry > Issue Type: Bug > Components: Sentry > Reporter: Ryan P > Assignee: Ryan P > > HiveSemanticAnalyzerHookContext no longer includes built-in functions as an > input to it's Read Entities. This change hides built in functions from > HiveAuthzBindingHook which is a huge security hole. > Failing to enforce the whitelist will allow users to execute such functions > as REFLECT and JAVA_METHOD. > https://cwiki.apache.org/confluence/display/Hive/ReflectUDF -- This message was sent by Atlassian JIRA (v6.3.4#6332)