PT-2017-4254 · Apache · Apache Hadoop

Published

2017-11-13

·

Updated

2020-08-24

·

CVE-2017-3166

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Hadoop versions 2.6.1 through 2.6.5 Apache Hadoop versions 2.7.0 through 2.7.3 Apache Hadoop version 3.0.0-alpha1
Description The issue is related to incorrect file permission assignments in Apache Hadoop. This can allow a remote attacker to bypass file access restrictions. If a file in an encryption zone with world-readable access permissions is localized via YARN's localization mechanism, it will be stored in a world-readable location and can be shared with any application that requests to localize that file.
Recommendations For Apache Hadoop versions 2.6.1 through 2.6.5, consider restricting access to files in encryption zones to prevent them from being stored in world-readable locations. For Apache Hadoop versions 2.7.0 through 2.7.3, restrict access to files in encryption zones to prevent them from being stored in world-readable locations. For Apache Hadoop version 3.0.0-alpha1, restrict access to files in encryption zones to prevent them from being stored in world-readable locations.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05255
CVE-2017-3166
GHSA-99QR-9CC9-FV2X

Affected Products

Apache Hadoop