Description
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0806 | In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file. |
Github GHSA |
GHSA-99qr-9cc9-fv2x | Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T23:41:26.878Z
Reserved: 2016-12-05T00:00:00.000Z
Link: CVE-2017-3166
No data.
Status : Modified
Published: 2017-11-13T14:29:00.870
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-3166
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA