CVE-2017-3166 Information

Description

In Apache Hadoop versions 2.6.1 to 2.6.5 2.7.0 to 2.7.3 and 3.0.0-alpha1 if a file in an encryption zone with access permissions that make it world readable is localized via YARN’s localization mechanism that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f@3Cgeneral.hadoop.apache.org3E https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@3Ccommits.druid.apache.org3E

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: