CVE-2015-1776
published 2016-04-19CVE-2015-1776: Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the…
PriorityP423medium6.2CVSS 3.0
AVLACLPRNUINSUCHINAN
EPSS
0.32%
24.1th percentile
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
ghsa·2022-05-17
CVE-2015-1776 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
osv·2022-05-17
CVE-2015-1776 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1776 hadoop: disclosure of encrypted data in Hadoop MapReduce [fedora-all]
bugzilla·2016-02-16·CVSS 6.2
CVE-2015-1776 [MEDIUM] CVE-2015-1776 hadoop: disclosure of encrypted data in Hadoop MapReduce [fedora-all]
CVE-2015-1776 hadoop: disclosure of encrypted data in Hadoop MapReduce [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2015-1776 hadoop: disclosure of encrypted data in Hadoop MapReduce
bugzilla·2016-02-16·CVSS 6.2
CVE-2015-1776 [MEDIUM] CVE-2015-1776 hadoop: disclosure of encrypted data in Hadoop MapReduce
CVE-2015-1776 hadoop: disclosure of encrypted data in Hadoop MapReduce
The encryption key/secret used to encrypt the intermediate data
generated by an Apache Hadoop MapReduce job is stored as a token in
the job’s credentials and are subsequently serialized to disk (
without any additional encryption/protection ) into the machine's
local dirs. A malicious user who has access to this credentials file
can load the tokens from the file, read the secret and then decrypt
the intermediate data which is also stored in machine local dirs.
External reference:
http://seclists.org/oss-sec/2016/q1/344
Discussion:
Created hadoop tracking bugs for this issue:
Affects: fedora-all [bug 1308836]
---
This vulnerability apply to a feature added to Hadoop in 2.6.x versions, which are not available in F
arXiv
A Non-Intrusive and Context-Based Vulnerability Scoring Framework for Cloud Services
arxiv_fulltext·2016-12-07
A Non-Intrusive and Context-Based Vulnerability Scoring Framework for Cloud Services
-1emA Non-Intrusive and Context-Based Vulnerability Scoring
Framework for Cloud Services
Hao Zhuang, Florian Pydde
EPFL
## Abstract
Understanding the severity of vulnerabilities within
cloud services is particularly important
for today's service administrators.
Although many systems, , CVSS, have been built to evaluate
and score the severity of vulnerabilities for administrators,
the scoring schemes employed by these systems fail to take into account
the contextual information of specific services having
these vulnerabilities, such as what roles they play in a particular
service. Such a deficiency makes resulting scores unhelpful.
This paper presents a practical framework, ,
that offers automatic and contextual scoring mechanism
to evaluate the severity of vulnerabilities
for a particu
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
- Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
- Internet Explorer: MS14-021 for CVE-2014-1776, Qualys ID: 100191
- MS14-012 for CVE-201
http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA%40mail.gmail.com%3Ehttp://www.securityfocus.com/bid/83259http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA%40mail.gmail.com%3Ehttp://www.securityfocus.com/bid/83259
2016-04-19
Published