CVE-2017-3166

HIGH

Apache Hadoop < 2.7.3 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 43.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (14)
apache/hadoop 2.6.1
apache/hadoop 2.6.2
apache/hadoop 2.6.3
apache/hadoop 2.6.4
apache/hadoop 2.6.5
apache/hadoop 2.7.0
apache/hadoop 2.7.1
apache/hadoop 2.7.2
apache/hadoop 2.7.3
apache/hadoop 3.0.0 alpha1
... and 4 more
Published Nov 13, 2017
Tracked Since Feb 18, 2026