CVE-2014-3627
published 2014-12-05CVE-2014-3627: The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.00%
86.0th percentile
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hadoop: file disclosure flaw
vendor_redhat·2014-11-21·CVSS 5.0
CVE-2014-3627 [MEDIUM] hadoop: file disclosure flaw
hadoop: file disclosure flaw
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.
Statement: This issue may affect the versions of hadoop as shipped with Red Hat Enterprise Virtualization Manager. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: jasperreports-server-pro (Red Hat Enterprise Vir
OSV
Improper Link Resolution Before File Access in Apache Hadoop
osv·2022-05-17
CVE-2014-3627 [MEDIUM] Improper Link Resolution Before File Access in Apache Hadoop
Improper Link Resolution Before File Access in Apache Hadoop
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.
GHSA
Improper Link Resolution Before File Access in Apache Hadoop
ghsa·2022-05-17
CVE-2014-3627 [MEDIUM] CWE-59 Improper Link Resolution Before File Access in Apache Hadoop
Improper Link Resolution Before File Access in Apache Hadoop
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3627 hadoop: file disclosure flaw
bugzilla·2014-12-04·CVSS 5.0
CVE-2014-3627 [MEDIUM] CVE-2014-3627 hadoop: file disclosure flaw
CVE-2014-3627 hadoop: file disclosure flaw
The Hadoop 2.5.2 release fixes the following flaw that would allow arbitrary files to be exposed:
""
Vulnerability allows a cluster user to expose private files owned
by the user running the YARN NodeManager process. The malicious cluster
user can create a public tar archive containing a symlink to a local file
on the node owned by the user running the YARN NodeManager process. The
permissions of the local file will be changed to be world-readable when the
public archive is localized on the node.
""
References:
http://seclists.org/oss-sec/2014/q4/891
http://mail-archives.apache.org/mod_mbox/hadoop-general/201411.mbox/%3CCALwhT97dOi04aC3VbekaB+zn2UAS_OZV2EAiP78GmjnMzfp2Ug@mail.gmail.com%3E
Discussion:
Created hadoop tracking bugs for this iss
Bugzilla
CVE-2014-3627 hadoop: file disclosure flaw [fedora-all]
bugzilla·2014-12-04·CVSS 5.0
CVE-2014-3627 [MEDIUM] CVE-2014-3627 hadoop: file disclosure flaw [fedora-all]
CVE-2014-3627 hadoop: file disclosure flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one
http://mail-archives.apache.org/mod_mbox/hadoop-general/201411.mbox/%3CCALwhT97dOi04aC3VbekaB+zn2UAS_OZV2EAiP78GmjnMzfp2Ug%40mail.gmail.com%3Ehttp://secunia.com/advisories/60079http://secunia.com/advisories/60432http://mail-archives.apache.org/mod_mbox/hadoop-general/201411.mbox/%3CCALwhT97dOi04aC3VbekaB+zn2UAS_OZV2EAiP78GmjnMzfp2Ug%40mail.gmail.com%3Ehttp://secunia.com/advisories/60079http://secunia.com/advisories/60432
2014-12-05
Published