Privilege Escalation Vulnerability in Apache Hadoop
CVE-2017-3166

7.8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
13 November 2017

Summary

In specific versions of Apache Hadoop, a vulnerability exists where files within an encryption zone, if given world-readable access permissions, can be localized through YARN's mechanism. This results in such files being stored in a location that is accessible to all applications requesting to localize the file. This flaw can lead to unauthorized access and data exposure, posing a significant risk to sensitive information.

Affected Version(s)

Apache Hadoop 2.6.1 to 2.6.5

Apache Hadoop 2.7.0 to 2.7.3

Apache Hadoop 3.0.0-alpha1 to 3.0.0-alpha3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.