Skip to content
Apache HadoopGHSA-f5fw-25gw-5m92

Apache Hadoop: Temporary File Local Information Disclosure

Low3.3CVE-2024-23454 · Published Sep 25, 2024 · updated Sep 10, 2026

Apache Hadoop’s `RunJar.run()` does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary directory is shared between all local users. As such, files written in this directory, without setting the correct posix permissions explicitly, may be viewable by all other local users.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
< 3.4.03.4.0
Details and references

More Apache Hadoop advisories

All Apache Hadoop
Advisory
Apache Hadoop argument injection vulnerability
Critical9.8Aug 5, 2022
Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
Critical9.8Jun 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium6.2May 17, 2022
Improper Access Control in Apache Hadoop
High8.8May 17, 2022
Improper Authentication in Apache Hadoop
LowMay 17, 2022
Improper Authentication in Apache Hadoop
Medium6.5May 17, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.