[ https://issues.apache.org/jira/browse/HIVE-3591?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13747571#comment-13747571 ]
Larry McCay commented on HIVE-3591: ----------------------------------- It appears that System properties can override conf vars too. I assume that we should leverage the restrictList there as well. > set hive.security.authorization.enabled can be executed by any user > ------------------------------------------------------------------- > > Key: HIVE-3591 > URL: https://issues.apache.org/jira/browse/HIVE-3591 > Project: Hive > Issue Type: Bug > Components: Authorization, CLI, Clients, JDBC > Affects Versions: 0.7.1 > Environment: RHEL 5.6 > CDH U3 > Reporter: Dev Gupta > Labels: Authorization, Security > > The property hive.security.authorization.enabled can be set to true or false, > by any user on the CLI, thus circumventing any previously set grants and > authorizations. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: http://www.atlassian.com/software/jira