Privilege Escalation Vulnerability in Apache Hadoop
CVE-2017-3166
7.8HIGH
What is CVE-2017-3166?
In specific versions of Apache Hadoop, a vulnerability exists where files within an encryption zone, if given world-readable access permissions, can be localized through YARN's mechanism. This results in such files being stored in a location that is accessible to all applications requesting to localize the file. This flaw can lead to unauthorized access and data exposure, posing a significant risk to sensitive information.
Affected Version(s)
Apache Hadoop 2.6.1 to 2.6.5
Apache Hadoop 2.7.0 to 2.7.3
Apache Hadoop 3.0.0-alpha1 to 3.0.0-alpha3