CVE-2016-5001
published 2017-08-30CVE-2016-5001: This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.63%
46.6th percentile
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | <= 2.6.3 | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
osv·2022-05-13
CVE-2016-5001 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
ghsa·2022-05-13
CVE-2016-5001 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5001 hadoop: Information disclosure [fedora-all]
bugzilla·2016-12-19·CVSS 5.5
CVE-2016-5001 [MEDIUM] CVE-2016-5001 hadoop: Information disclosure [fedora-all]
CVE-2016-5001 hadoop: Information disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
o
Bugzilla
CVE-2016-5001 hadoop: Information disclosure
bugzilla·2016-12-19·CVSS 5.5
CVE-2016-5001 [MEDIUM] CVE-2016-5001 hadoop: Information disclosure
CVE-2016-5001 hadoop: Information disclosure
This is an information disclosure vulnerability in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.
References:
http://seclists.org/oss-sec/2016/q4/698
Discussion:
Created hadoop tracking bugs for this issue:
Affects: fedora-all [bug 1405925]
---
This will be fixed by Hadoop 2.7.3 in F26, but I'm not sure much can really be done about F25 and earlier with Hadoop 2.4.1. Upstream does not have a fix which can be easily-backported and the current package maintainer doesn't have time to research a custom fix.
---
This CVE Bugzilla entry is for community support informational purposes only
http://seclists.org/oss-sec/2016/q4/698http://www.securityfocus.com/bid/94950https://lists.apache.org/thread.html/r66de86b9a608c1da70b2d27d765c11ec88edf6e5dd6f379ab33e072a%40%3Cuser.flink.apache.org%3Ehttp://seclists.org/oss-sec/2016/q4/698http://www.securityfocus.com/bid/94950https://lists.apache.org/thread.html/r66de86b9a608c1da70b2d27d765c11ec88edf6e5dd6f379ab33e072a%40%3Cuser.flink.apache.org%3E
2017-08-30
Published