Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g48f-ff5h-5f64

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.2

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.

Пакеты

Наименование

org.apache.hadoop:hadoop-common

maven
Затронутые версииВерсия исправления

>= 2.6.0, <= 2.6.4

2.6.5

EPSS

Процентиль: 20%
0.00065
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.2
nvd
почти 10 лет назад

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.

CVSS3: 6.2
debian
почти 10 лет назад

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduc ...

EPSS

Процентиль: 20%
0.00065
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-200