GHSA-w4x9-4f5x-8jj8

Suggest an improvement
Source
https://github.com/advisories/GHSA-w4x9-4f5x-8jj8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-w4x9-4f5x-8jj8/GHSA-w4x9-4f5x-8jj8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w4x9-4f5x-8jj8
Aliases
  • CVE-2014-0228
Published
2018-11-21T22:23:29Z
Modified
2024-12-02T05:44:47.759409Z
Summary
Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
Details

Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-284"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:59:37Z"
}
References

Affected packages

Maven / org.apache.hive:hive

Package

Name
org.apache.hive:hive
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.13.1

Affected versions

0.*

0.13.0

Maven / org.apache.hive:hive-exec

Package

Name
org.apache.hive:hive-exec
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive-exec

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.13.1

Affected versions

0.*

0.8.0
0.8.1
0.9.0
0.10.0
0.11.0
0.12.0
0.13.0

Maven / org.apache.hive:hive-service

Package

Name
org.apache.hive:hive-service
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive-service

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.13.1

Affected versions

0.*

0.8.0
0.8.1
0.9.0
0.10.0
0.11.0
0.12.0
0.13.0