Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /home/zhenxiangba/zhenxiangba.com/public_html/phproxy-improved-master/index.php on line 456
CVE-2017-15713: Apache Hadoop MapReduce job history server vulnerability
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
CVE-2017-15713: Apache Hadoop MapReduce job history server vulnerability
- To: general@xxxxxxxxxxxxxxxxx, user@xxxxxxxxxxxxxxxxx, Hadoop Common <common-dev@xxxxxxxxxxxxxxxxx>, "<security@xxxxxxxxxxxxxxxxx>" <security@xxxxxxxxxxxxxxxxx>, full-disclosure@xxxxxxxxxxxxxxxxx, bugtraq@xxxxxxxxxxxxxxxxx, oss-security@xxxxxxxxxxxxxxxxxx
- Subject: CVE-2017-15713: Apache Hadoop MapReduce job history server vulnerability
- From: Jason Lowe <jlowe@xxxxxxxxxx>
- Date: Fri, 19 Jan 2018 08:46:40 -0600
CVE-2017-15713: Apache Hadoop MapReduce job history server vulnerability
Severity: Severe
Vendor: The Apache Software Foundation
Versions Affected:
Hadoop 0.23.0 to 0.23.11
Hadoop 2.0.0-alpha to 2.8.2
Hadoop 3.0.0-alpha to 3.0.0-beta1
Users affected: Users running the MapReduce job history server daemon
Impact: Vulnerability allows a cluster user to expose private files
owned by the user running the MapReduce job history server process.
The malicious user can construct a configuration file containing XML
directives that reference sensitive files on the MapReduce job history
server host.
Mitigation: Users should upgrade to Apache Hadoop 2.7.5, 2.8.3, 2.9.0, or 3.0.0.
Credit: This issue was discovered by Man Yue Mo of lgtm.com