Skip to content
Apache HadoopGHSA-7q56-mp4c-gggg

Improper Access Control in Apache Hadoop

High8.8CVE-2016-5393 · Published May 17, 2022 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
>= 2.6.0, < 2.6.52.6.5
>= 2.7.0, < 2.7.32.7.3
Details and references

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-284
Also known as
CVE-2016-5393

More Apache Hadoop advisories

All Apache Hadoop
DateAdvisory
May 172022Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
CVE-2017-7669High7.5fixed in 2.8.1, 3.0.0-alpha3
May 172022Improper Authentication in Apache Hadoop
CVE-2014-0229Medium6.5fixed in 0.23.11, 2.4.1
May 172022Improper Authentication in Apache Hadoop
CVE-2013-2192Lowfixed in 0.23.9, 2.0.6-alpha
May 172022Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2015-1776Medium6.2fixed in 2.6.5
May 142022Insecure Inherited Permissions in Apache Hadoop
CVE-2016-6811High8.8fixed in 2.7.4
May 132022Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-5001Medium5.5fixed in 2.6.4, 2.7.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.