Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.
References
Configurations
Information
Published : 2014-11-16 09:59
Updated : 2018-10-09 12:41
NVD link : CVE-2014-0228
Mitre link : CVE-2014-0228
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
apache
- hive