VYPR
Medium severity4.3NVD Advisory· Published Nov 8, 2018· Updated Jun 17, 2026

CVE-2018-1314

CVE-2018-1314

Description

In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.hive:hive-jdbcMaven
< 2.3.42.3.4
org.apache.hive:hive-jdbcMaven
>= 3.0.0, < 3.1.13.1.1

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.