Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3627

Опубликовано: 21 нояб. 2014
Источник: redhat
CVSS2: 6.4
EPSS Низкий

Описание

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.

Отчет

This issue may affect the versions of hadoop as shipped with Red Hat Enterprise Virtualization Manager. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 3jasperreports-server-proUnder investigation
Red Hat JBoss Enterprise Web Server 1fuse-6Not affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-enterprise-7Not affected
Red Hat JBoss Enterprise Web Server 1fuse-mq-enterprise-7Not affected

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 81%
0.01616
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

nvd
около 11 лет назад

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.

github
больше 3 лет назад

Improper Link Resolution Before File Access in Apache Hadoop

EPSS

Процентиль: 81%
0.01616
Низкий

6.4 Medium

CVSS2