PT-2016-6406 · Apache · Apache Hadoop

Freddie Rice

·

Published

2016-11-29

·

Updated

2022-05-17

·

CVE-2016-5393

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Hadoop versions 2.6.x through 2.6.4 Apache Hadoop versions 2.7.x through 2.7.2
Description A remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
Recommendations For Apache Hadoop versions 2.6.x through 2.6.4, update to version 2.6.5 or later. For Apache Hadoop versions 2.7.x through 2.7.2, update to version 2.7.3 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-5393
GHSA-7Q56-MP4C-GGGG

Affected Products

Apache Hadoop