CVE-2017-15713
MEDIUMApache Hadoop Sensitive Information Exposure via Malicious Configuration
Title source: llmDescription
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
References (1)
Core 1
Core References
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/a790a251ace7213bde9f69777dedb453b1a01a6d18289c14a61d4f91%40%3Cgeneral.hadoop.apache.org%3E
Scores
CVSS v3
6.5
EPSS
0.0019
EPSS Percentile
40.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (12)
apache/hadoop
2.0.0 alpha
apache/hadoop
2.0.1 alpha
apache/hadoop
2.0.2 alpha
apache/hadoop
2.0.3 alpha
apache/hadoop
2.0.4 alpha
apache/hadoop
2.0.5 alpha
apache/hadoop
2.0.6 alpha
apache/hadoop
2.1.0 beta
apache/hadoop
2.1.1 beta
apache/hadoop
3.0.0 alpha1 (5 CPE variants)
... and 2 more
Published
Jan 19, 2018
Tracked Since
Feb 18, 2026