Vulnerability CVE-2016-5001


Published: 2017-08-30   Modified: 2017-08-31

Description:
This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Apache -> Hadoop 

 References:
http://seclists.org/oss-sec/2016/q4/698
http://www.securityfocus.com/bid/94950

Copyright 2024, cxsecurity.com

 

Back to Top