Apache HiveGHSA-w4x9-4f5x-8jj8
Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
LowCVE-2014-0228 · Published Nov 21, 2018 · updated Dec 2, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hive:hive-exec Maven | < 0.13.1 | 0.13.1 |
Details and references
Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- CVE-2014-0228
- nvd.nist.gov/vuln/detail/CVE-2014-0228
- github.com/advisories/GHSA-w4x9-4f5x-8jj8
- mail-archives.apache.org/mod_mbox/hive-user/201406.mbox/%3CCABgNGzeN7E+9d=YV5yvnKA7wmSx1op_avtUjPcPtDaR6DLJM6g@mail.gmail.com%3E
- packetstormsecurity.com/files/127091/Apache-Hive-0.13.0-Authorization-Failure.html
- www.securityfocus.com/archive/1/532418/100/0/threaded
More Apache Hive advisories
All Apache Hive| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 212018 | High severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service CVE-2015-7521High8.3fixed in 1.2.2 | High8.3 | 1.2.2 |
| Nov 212018 | Incorrect Permission Assignment for Critical Resource in Apache hive CVE-2018-1315Low3.7fixed in 2.3.3 | Low3.7 | 2.3.3 |
| Nov 212018 | Exposure of Sensitive Information to an Unauthorized Actor in Apache hive CVE-2018-1284Low3.7fixed in 2.3.3 | Low3.7 | 2.3.3 |
| Nov 212018 | Improper Authentication in hive:hive-exec CVE-2018-11777High8.1fixed in 2.3.4, 3.1.1 | High8.1 | 2.3.4, 3.1.1 |
| Mar 142019 | Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service CVE-2017-12625Medium4.3fixed in 2.1.2, 2.2.1, 2.3.1 | Medium4.3 | 2.1.2, 2.2.1, 2.3.1 |
| Mar 142019 | org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service vulnerable to Improper Certificate Validation CVE-2016-3083High7.5fixed in 1.2.2, 2.0.1 | High7.5 | 1.2.2, 2.0.1 |