CVE-2014-0228

Published Nov 16, 2014

Last updated a year ago

Overview

Description
Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
3.5
Impact score
2.9
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-284

Social media

Hype score
Not currently trending

Configurations