6.5
CVSSv3

CVE-2017-15713

Published: 19/01/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Vulnerability in Apache Hadoop 0.23.x, 2.x prior to 2.7.5, 2.8.x prior to 2.8.3, and 3.0.0-alpha up to and including 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache hadoop 2.0.4

apache hadoop 2.0.3

apache hadoop 2.0.6

apache hadoop 2.1.0

apache hadoop 2.0.5

apache hadoop 2.1.1

apache hadoop 2.0.0

apache hadoop 3.0.0

apache hadoop 2.0.2

apache hadoop 2.0.1

apache hadoop