Description
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0806 | In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file. |
Github GHSA |
GHSA-99qr-9cc9-fv2x | Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T23:41:26.878Z
Reserved: 2016-12-05T00:00:00.000Z
Link: CVE-2017-3166
No data.
Status : Deferred
Published: 2017-11-13T14:29:00.870
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-3166
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA