VYPR
Low severityNVD Advisory· Published Nov 16, 2014· Updated May 6, 2026

CVE-2014-0228

CVE-2014-0228

Description

Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.hive:hiveMaven
< 0.13.10.13.1
org.apache.hive:hive-execMaven
< 0.13.10.13.1
org.apache.hive:hive-serviceMaven
< 0.13.10.13.1

Affected products

1
  • cpe:2.3:a:apache:hive:*:*:*:*:*:*:*:*
    Range: <=0.13.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.