Incorrect default permissions in Hadoop - CVE-2024-23454

 

Incorrect default permissions in Hadoop - CVE-2024-23454

Published: September 26, 2024


Vulnerability identifier: #VU97712
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-23454
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available
Affected software:
Hadoop
Log Analysis
Netcool Operations Insight
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
watsonx.data
IBM Cloud Pak System
Db2 Big SQL
IBM OpenPages with Watson
IBM QRadar Incident Forensics
openEuler
hadoop-3.1-yarn
hadoop-3.1-debugsource
hadoop-3.1-tests
hadoop-3.1-maven-plugin
hadoop-3.1-mapreduce-examples
hadoop-3.1-mapreduce
hadoop-3.1-httpfs
hadoop-3.1-hdfs
hadoop-3.1-common
hadoop-3.1-client
libhdfs
hadoop-3.1-yarn-security
hadoop-3.1-devel
hadoop-3.1
hadoop-3.1-common-native
hadoop-3.1-debuginfo
hadoop-yarn-security
hadoop-yarn
hadoop-tests
hadoop-maven-plugin
hadoop-mapreduce-examples
hadoop-mapreduce
hadoop-httpfs
hadoop-hdfs
hadoop-common
hadoop-client
hadoop-devel
hadoop-debugsource
hadoop-debuginfo
hadoop-common-native
hadoop
IBM Qradar SIEM
IBM DB2

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to the RunJar.run() method does not set permissions for temporary directory by default. A local user with access to the system can view contents of files and directories.


How to mitigate CVE-2024-23454

Install updates from vendor's website.

Sources