Apache HadoopGHSA-8r28-r8cp-g6cp
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium5.5CVE-2016-5001 · Published May 13, 2022 · updated Nov 8, 2023
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hadoop:hadoop-common Maven | < 2.6.4 | 2.6.4 |
| >= 2.7.0, < 2.7.2 | 2.7.2 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- CVE-2016-5001
More Apache Hadoop advisories
All Apache Hadoop| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop | Medium6.2 | 2.6.5 |
| May 172022 | Improper Access Control in Apache Hadoop | High8.8 | 2.6.5+1 more |
| May 172022 | Improper Authentication in Apache Hadoop | Low | 0.23.9+1 more |
| May 172022 | Improper Authentication in Apache Hadoop | Medium6.5 | 0.23.11+1 more |
| May 172022 | Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation | High7.5 | 2.8.1+1 more |
| May 142022 | Insecure Inherited Permissions in Apache Hadoop | High8.8 | 2.7.4 |