CVE-2017-3166 Information
Feb 14, 2021
cve
Description
In Apache Hadoop versions 2.6.1 to 2.6.5 2.7.0 to 2.7.3 and 3.0.0-alpha1 if a file in an encryption zone with access permissions that make it world readable is localized via YARN’s localization mechanism that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f@3Cgeneral.hadoop.apache.org3E https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@3Ccommits.druid.apache.org3E
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: