Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache hadoop 2.7.0 vulnerabilities and exploits
(subscribe to this query)
187
VMScore
CVE-2016-5001
This is an information disclosure vulnerability in Apache Hadoop prior to 2.6.4 and 2.7.x prior to 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessin...
Apache Hadoop 2.7.0
Apache Hadoop
Apache Hadoop 2.7.1
409
VMScore
CVE-2015-7430
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 prior to 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecified vectors.
Apache Hadoop 2.5.0
Apache Hadoop 1.1.1
Apache Hadoop 2.7.0
Apache Hadoop 2.4.0
578
VMScore
CVE-2016-5393
In Apache Hadoop 2.6.x prior to 2.6.5 and 2.7.x prior to 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
Apache Hadoop 2.7.1
Apache Hadoop 2.7.2
Apache Hadoop 2.7.0
Apache Hadoop 2.6.4
Apache Hadoop 2.6.2
Apache Hadoop 2.6.0
Apache Hadoop 2.6.3
Apache Hadoop 2.6.1
445
VMScore
CVE-2016-3086
The YARN NodeManager in Apache Hadoop 2.6.x prior to 2.6.5 and 2.7.x prior to 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Apache Hadoop 2.6.2
Apache Hadoop 2.6.4
Apache Hadoop 2.7.0
Apache Hadoop 2.7.1
Apache Hadoop 2.7.2
Apache Hadoop 2.6.0
Apache Hadoop 2.6.1
Apache Hadoop 2.6.3
409
VMScore
CVE-2017-3166
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be sh...
Apache Hadoop 2.6.2
Apache Hadoop 2.7.0
Apache Hadoop 2.6.3
Apache Hadoop 2.6.4
Apache Hadoop 3.0.0
Apache Hadoop 2.7.2
Apache Hadoop 2.7.1
Apache Hadoop 2.6.1
Apache Hadoop 2.6.5
Apache Hadoop 2.7.3
383
VMScore
CVE-2017-3161
The HDFS web UI in Apache Hadoop prior to 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.
Apache Hadoop
668
VMScore
CVE-2017-3162
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop prior to 2.7.0.
Apache Hadoop
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22460
CVE-2024-4646
CVE-2024-29212
IMAP
CVE-2023-36672
CVE-2024-34547
command injection
CVE-2024-4651
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started