Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown
CVE-2012-2945
Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Hadoop 1.0.3 contains a symlink vulnerability.
0
Attacker Value
Unknown
CVE-2019-17195
Disclosure Date: October 15, 2019 (last updated November 08, 2023)
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
0
Attacker Value
Unknown
CVE-2018-11768
Disclosure Date: October 04, 2019 (last updated November 08, 2023)
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
0
Attacker Value
Unknown
CVE-2018-8029
Disclosure Date: May 30, 2019 (last updated November 08, 2023)
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
0
Attacker Value
Unknown
CVE-2018-11767
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.
0
Attacker Value
Unknown
CVE-2018-1296
Disclosure Date: February 07, 2019 (last updated November 08, 2023)
In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.
0
Attacker Value
Unknown
CVE-2018-11766
Disclosure Date: November 27, 2018 (last updated November 08, 2023)
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.
0
Attacker Value
Unknown
CVE-2018-8009
Disclosure Date: November 13, 2018 (last updated November 08, 2023)
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
0
Attacker Value
Unknown
CVE-2017-15718
Disclosure Date: January 24, 2018 (last updated November 08, 2023)
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
0
Attacker Value
Unknown
CVE-2017-15713
Disclosure Date: January 19, 2018 (last updated November 08, 2023)
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
0