CVE-2018-1296
07.02.2019, 22:29
In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.Enginsight
Vendor | Product | Version |
---|---|---|
apache | hadoop | 2.5.0 ≤ 𝑥 ≤ 2.7.5 |
apache | hadoop | 2.8.0 |
apache | hadoop | 2.8.1 |
apache | hadoop | 2.8.2 |
apache | hadoop | 2.8.3 |
apache | hadoop | 2.9.0 |
apache | hadoop | 3.0.0 |
apache | hadoop | 3.0.0:alpha1 |
apache | hadoop | 3.0.0:alpha2 |
apache | hadoop | 3.0.0:alpha3 |
apache | hadoop | 3.0.0:alpha4 |
apache | hadoop | 3.0.0:beta1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References