Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache hadoop 2.7.1 vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2017-3166
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be sh...
Apache Hadoop 2.6.2
Apache Hadoop 2.7.0
Apache Hadoop 2.6.3
Apache Hadoop 2.6.4
Apache Hadoop 3.0.0
Apache Hadoop 2.7.2
Apache Hadoop 2.7.1
Apache Hadoop 2.6.1
Apache Hadoop 2.6.5
Apache Hadoop 2.7.3
9.8
CVSSv3
CVE-2016-3086
The YARN NodeManager in Apache Hadoop 2.6.x prior to 2.6.5 and 2.7.x prior to 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Apache Hadoop 2.6.0
Apache Hadoop 2.6.2
Apache Hadoop 2.7.0
Apache Hadoop 2.6.3
Apache Hadoop 2.6.4
Apache Hadoop 2.7.2
Apache Hadoop 2.7.1
Apache Hadoop 2.6.1
5.5
CVSSv3
CVE-2016-5001
This is an information disclosure vulnerability in Apache Hadoop prior to 2.6.4 and 2.7.x prior to 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessin...
Apache Hadoop 2.7.0
Apache Hadoop
Apache Hadoop 2.7.1
8.8
CVSSv3
CVE-2016-5393
In Apache Hadoop 2.6.x prior to 2.6.5 and 2.7.x prior to 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
Apache Hadoop 2.7.0
Apache Hadoop 2.7.2
Apache Hadoop 2.7.1
Apache Hadoop 2.6.0
Apache Hadoop 2.6.2
Apache Hadoop 2.6.3
Apache Hadoop 2.6.4
Apache Hadoop 2.6.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started