Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could…
apache·CWE-208·Published 2021-03-16