Privilege Escalation Vulnerability in Apache Hadoop
CVE-2017-3166
7.8HIGH
Summary
In specific versions of Apache Hadoop, a vulnerability exists where files within an encryption zone, if given world-readable access permissions, can be localized through YARN's mechanism. This results in such files being stored in a location that is accessible to all applications requesting to localize the file. This flaw can lead to unauthorized access and data exposure, posing a significant risk to sensitive information.
Affected Version(s)
Apache Hadoop 2.6.1 to 2.6.5
Apache Hadoop 2.7.0 to 2.7.3
Apache Hadoop 3.0.0-alpha1 to 3.0.0-alpha3
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved