cbcvebase.
CVE-2017-15713
published 2018-01-19

CVE-2017-15713: Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files…

medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop0.23.0 – 0.23.11
apachehadoop2.2.0 – 2.8.2
apache_software_foundationapache_hadoop
apache_software_foundationapache_hadoop
apache_software_foundationapache_hadoop