Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpmf-8cj2-595g

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Link Resolution Before File Access in Apache Hadoop

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.

Пакеты

Наименование

org.apache.hadoop:hadoop-client

maven
Затронутые версииВерсия исправления

>= 0.23.0, < 1.0.1

1.0.1

Наименование

org.apache.hadoop:hadoop-client

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.5.2

2.5.2

EPSS

Процентиль: 81%
0.01616
Низкий

Дефекты

CWE-59

Связанные уязвимости

redhat
около 11 лет назад

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.

nvd
около 11 лет назад

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.

EPSS

Процентиль: 81%
0.01616
Низкий

Дефекты

CWE-59