← Back

CVE-2017-15713

nvd nist
Published: Jan 19, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.

Affected (16)

Products: Apache: Hadoop
1 product
Hadoop
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 0.23.0 to 0.23.11
From 2.2.0 to 2.8.2
Version 2.0.0 alpha
Version 2.0.1 alpha
Version 2.0.2 alpha
Version 2.0.3 alpha
Version 2.0.4 alpha
Version 2.0.5 alpha
Version 2.0.6 alpha
Version 2.1.0 beta
Version 2.1.1 beta
Version 3.0.0 alpha1
Version 3.0.0 alpha2
Version 3.0.0 alpha3
Version 3.0.0 alpha4
Version 3.0.0 beta1

Timeline

No history available yet.