GHSA-w4x9-4f5x-8jj8
Dashboard / Vulnerabilities / GHSA-w4x9-4f5x-8jj8
Summary: Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
Details: Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-0228, https://github.com/advisories/GHSA-w4x9-4f5x-8jj8, http://mail-archives.apache.org/mod_mbox/hive-user/201406.mbox/%3CCABgNGzeN7E+9d=YV5yvnKA7wmSx1op_avtUjPcPtDaR6DLJM6g@mail.gmail.com%3E, http://packetstormsecurity.com/files/127091/Apache-Hive-0.13.0-Authorization-Failure.html, http://www.securityfocus.com/archive/1/532418/100/0/threaded
Affected packages
Package
Name: org.apache.hive:hive
Purl: pkg:maven/org.apache.hive/hive
Affected ranges
Type: ECOSYSTEM
Events:
