{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "file disclosure flaw",
    "tracking": {
      "current_release_date": "2026-08-11T14:05:00+00:00",
      "generator": {
        "date": "2026-08-11T14:05:00+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-3627",
      "initial_release_date": "2014-11-21T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:05:00+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Virtualization 3.6.0",
            "product": {
              "name": "Red Hat Enterprise Virtualization 3.6.0",
              "product_id": "rhev-m-3",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhev_v2v:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jasperreports-server-pro",
            "product": {
              "name": "jasperreports-server-pro",
              "product_id": "jasperreports-server-pro.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jasperreports-server-pro?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jasperreports-server-pro.src as a component of Red Hat Enterprise Virtualization 3.6.0",
          "product_id": "rhev-m-3:jasperreports-server-pro.src"
        },
        "product_reference": "jasperreports-server-pro.src",
        "relates_to_product_reference": "rhev-m-3"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-3627",
      "discovery_date": "2014-12-03T00:00:00+00:00",
      "notes": [
        {
          "category": "other",
          "text": "This issue may affect the versions of hadoop as shipped with Red Hat Enterprise Virtualization Manager. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "under_investigation": [
          "rhev-m-3:jasperreports-server-pro.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-3627"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3627"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-3627"
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
            "baseScore": 6.4
          },
          "products": [
            "rhev-m-3:jasperreports-server-pro.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhev-m-3:jasperreports-server-pro.src"
          ]
        }
      ],
      "title": "file disclosure flaw"
    }
  ]
}