CVE-2017-15713
published 2018-01-19CVE-2017-15713: Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files…
PriorityP337medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
2.21%
80.7th percentile
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | 0.23.0 – 0.23.11 | — |
| apache | hadoop | 2.2.0 – 2.8.2 | — |
| apache_software_foundation | apache_hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_apache6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
osv·2018-12-21
CVE-2017-15713 [MEDIUM] Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
GHSA
Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
ghsa·2018-12-21
CVE-2017-15713 [MEDIUM] CWE-200 Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Apache
Apache hadoop: CVE-2017-15713
vendor_apache·CVSS 6.5
CVE-2017-15713 [MEDIUM] Apache hadoop: CVE-2017-15713
Apache hadoop: CVE-2017-15713
Vulnerability allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Apache
Apache hadoop: CVE-2018-11767
vendor_apache·CVSS 6.5
CVE-2018-11767 [MEDIUM] Apache hadoop: CVE-2018-11767
Apache hadoop: CVE-2018-11767
After the security fix for CVE-2017-15713, KMS has an access control regression, blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms such as LdapGroupsMapping, CompositeGroupsMapping, or NullGroupsMapping.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11767 hadoop: Apache Hadoop KMS ACL regression
bugzilla·2019-04-04·CVSS 6.5
CVE-2018-11767 [MEDIUM] CVE-2018-11767 hadoop: Apache Hadoop KMS ACL regression
CVE-2018-11767 hadoop: Apache Hadoop KMS ACL regression
After the security fix for CVE-2017-15713, KMS has an access control regression, blocking users or granting access to users incorrectly, if the system
uses non-default groups mapping mechanisms such as LdapGroupsMapping, CompositeGroupsMapping, or NullGroupsMapping.
References:
https://seclists.org/oss-sec/2019/q1/173
Discussion:
Created hadoop tracking bugs for this issue:
Affects: fedora-all [bug 1696004]
---
rhs-hadoop is no longer supported in Red Hat Gluster Storage 3. For additional information: https://access.redhat.com/documentation/en-us/red_hat_gluster_storage/3.1/html/3.1_update_3_release_notes/chap-documentation-3.1_update_3_release_notes-deprecations
---
This vulnerability is out of security support scope for th
Bugzilla
CVE-2017-15713 hadoop: Information disclosure in MapReduce job history server [fedora-all]
bugzilla·2018-01-23·CVSS 6.5
CVE-2017-15713 [MEDIUM] CVE-2017-15713 hadoop: Information disclosure in MapReduce job history server [fedora-all]
CVE-2017-15713 hadoop: Information disclosure in MapReduce job history server [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2017-15713 hadoop: Information disclosure in MapReduce job history server
bugzilla·2018-01-23·CVSS 6.5
CVE-2017-15713 [MEDIUM] CVE-2017-15713 hadoop: Information disclosure in MapReduce job history server
CVE-2017-15713 hadoop: Information disclosure in MapReduce job history server
A vulnerability was found in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Reference:
https://lists.apache.org/thread.html/a790a251ace7213bde9f69777dedb453b1a01a6d18289c14a61d4f91@%3Cgeneral.hadoop.apache.org%3E
Discussion:
Created hadoop tracking bugs for this issue:
Affects: fedora-all [bug 1537786]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not
2018-01-19
Published