7.8
CVSSv3

CVE-2017-3166

Published: 13/11/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.

Vulnerable Product Search on Vulmon Subscribe to Product

apache hadoop 2.6.2

apache hadoop 2.7.0

apache hadoop 2.6.3

apache hadoop 2.6.4

apache hadoop 3.0.0

apache hadoop 2.7.2

apache hadoop 2.7.1

apache hadoop 2.6.1

apache hadoop 2.6.5

apache hadoop 2.7.3