Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown

CVE-2012-2945

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Hadoop 1.0.3 contains a symlink vulnerability.
Attacker Value
Unknown

CVE-2019-17195

Disclosure Date: October 15, 2019 (last updated November 08, 2023)
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Attacker Value
Unknown

CVE-2018-11768

Disclosure Date: October 04, 2019 (last updated November 08, 2023)
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
Attacker Value
Unknown

CVE-2018-8029

Disclosure Date: May 30, 2019 (last updated November 08, 2023)
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
0
Attacker Value
Unknown

CVE-2018-11767

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.
0
Attacker Value
Unknown

CVE-2018-1296

Disclosure Date: February 07, 2019 (last updated November 08, 2023)
In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.
0
Attacker Value
Unknown

CVE-2018-11766

Disclosure Date: November 27, 2018 (last updated November 08, 2023)
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.
0
Attacker Value
Unknown

CVE-2018-8009

Disclosure Date: November 13, 2018 (last updated November 08, 2023)
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
0
Attacker Value
Unknown

CVE-2017-15718

Disclosure Date: January 24, 2018 (last updated November 08, 2023)
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
0
Attacker Value
Unknown

CVE-2017-15713

Disclosure Date: January 19, 2018 (last updated November 08, 2023)
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
0