CVE-2017-5646
Summary
| CVE | CVE-2017-5646 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-26 21:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit logged and can be easily associated with the authenticated user, this is still a serious security issue. All users are recommended to upgrade to the Apache Knox 0.12.0 release. |
Risk And Classification
Primary CVSS: v3.1 6.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-346 | Escalated Privileges and Data Access
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
| 2.0 | [email protected] | Primary | 4.9 | AV:N/AC:M/Au:S/C:P/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Knox | 0.10.0 | All | All | All |
| Application | Apache | Knox | 0.11.0 | All | All | All |
| Application | Apache | Knox | 0.2.0 | All | All | All |
| Application | Apache | Knox | 0.3.0 | All | All | All |
| Application | Apache | Knox | 0.4.0 | All | All | All |
| Application | Apache | Knox | 0.5.0 | All | All | All |
| Application | Apache | Knox | 0.6.0 | All | All | All |
| Application | Apache | Knox | 0.7.0 | All | All | All |
| Application | Apache | Knox | 0.8.0 | All | All | All |
| Application | Apache | Knox | 0.9.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Knox | affected 0.2.0 to 0.11.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Apache Knox CVE-2017-5646 User Impersonation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [ANNOUNCE] CVE-2017-5646: Apache Knox Impersonation Issue for WebHDFS | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.