Apache HadoopGHSA-g48f-ff5h-5f64
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium6.2CVE-2015-1776 · Published May 17, 2022 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hadoop:hadoop-common Maven | >= 2.6.0, < 2.6.5 | 2.6.5 |
Details and references
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- CVE-2015-1776
More Apache Hadoop advisories
All Apache Hadoop| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation CVE-2017-7669High7.5fixed in 2.8.1, 3.0.0-alpha3 | High7.5 | 2.8.1, 3.0.0-alpha3 |
| May 172022 | Improper Authentication in Apache Hadoop CVE-2014-0229Medium6.5fixed in 0.23.11, 2.4.1 | Medium6.5 | 0.23.11, 2.4.1 |
| May 172022 | Improper Authentication in Apache Hadoop CVE-2013-2192Lowfixed in 0.23.9, 2.0.6-alpha | Low | 0.23.9, 2.0.6-alpha |
| May 172022 | Improper Access Control in Apache Hadoop CVE-2016-5393High8.8fixed in 2.6.5, 2.7.3 | High8.8 | 2.6.5, 2.7.3 |
| May 142022 | Insecure Inherited Permissions in Apache Hadoop CVE-2016-6811High8.8fixed in 2.7.4 | High8.8 | 2.7.4 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop CVE-2016-5001Medium5.5fixed in 2.6.4, 2.7.2 | Medium5.5 | 2.6.4, 2.7.2 |