Cleartext transmission of sensitive information in Hadoop - CVE-2017-3166

 

Cleartext transmission of sensitive information in Hadoop - CVE-2017-3166

Published: November 13, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU37982
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3166
CWE-ID: CWE-319
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.


Affected software

Hadoop
Fedora
hadoop
IBM Cloud Application Performance Management (APM)

How to mitigate CVE-2017-3166

Install update from vendor's website.

hadoop - addressed in versions 2.7.6-2.fc28, 2.7.6-4.fc28
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins