CVE-2014-0228

low Apache
CVSS v3 Base Score
3.5
AV:N/AC:M/Au:S/C:P/I:N/A:N
EPSS Score
0.3%
Exploitation probability in 30 days
Top 45% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
P
Integrity
None
Availability
None
Published: November 16, 2014 (4197 days ago)
Last Modified: May 6, 2026
Vendor: Apache
Source: NVD

Description

Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.

CWE

CWE-284

Affected Products

apache hive

References