Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r28-r8cp-g6cp

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop

This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.

Пакеты

Наименование

org.apache.hadoop:hadoop-common

maven
Затронутые версииВерсия исправления

<= 2.6.3

2.6.4

Наименование

org.apache.hadoop:hadoop-common

maven
Затронутые версииВерсия исправления

>= 2.7.0, <= 2.7.1

2.7.2

EPSS

Процентиль: 31%
0.00118
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
nvd
больше 8 лет назад

This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.

CVSS3: 5.5
debian
больше 8 лет назад

This is an information disclosure vulnerability in Apache Hadoop befor ...

EPSS

Процентиль: 31%
0.00118
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200