CVE-2017-3166

7.8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
13 November 2017

Summary

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.

Affected Version(s)

Apache Hadoop 2.6.1 to 2.6.5

Apache Hadoop 2.7.0 to 2.7.3

Apache Hadoop 3.0.0-alpha1 to 3.0.0-alpha3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.