Skip to content
Apache HadoopGHSA-8r28-r8cp-g6cp

Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop

Medium5.5CVE-2016-5001 · Published May 13, 2022 · updated Nov 8, 2023

This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
< 2.6.42.6.4
>= 2.7.0, < 2.7.22.7.2
Details and references

More Apache Hadoop advisories

All Apache Hadoop
Advisory
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium6.2May 17, 2022
Improper Access Control in Apache Hadoop
High8.8May 17, 2022
Improper Authentication in Apache Hadoop
LowMay 17, 2022
Improper Authentication in Apache Hadoop
Medium6.5May 17, 2022
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
High7.5May 17, 2022
Insecure Inherited Permissions in Apache Hadoop
High8.8May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.