Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
BID:71466
Info
Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
| Bugtraq ID: | 71466 |
| Class: | Design Error |
| CVE: |
CVE-2014-3627 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2014 12:00AM |
| Updated: | Nov 21 2014 12:00AM |
| Credit: | Jason Lowe of Yahoo |
| Vulnerable: |
Apache Hadoop 2.0.5 Apache Hadoop 0.23.9 Apache Hadoop 0.23.8 Apache Hadoop 0.23.7 Apache Hadoop 0.23.6 Apache Hadoop 0.23.5 Apache Hadoop 0.23.4 Apache Hadoop 0.23.3 Apache Hadoop 0.23.1 Apache Hadoop 0.23 Apache Hadoop 2.5.1 Apache Hadoop 2.0 Apache Hadoop 0.23.11 |
| Not Vulnerable: |
Apache Hadoop 2.5.2 |
Discussion
Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
Apache Hadoop is prone to an information-disclosure vulnerability.
An attacker can exploit this issue by creating a symlink to a local file and gain access to sensitive information that may lead to further attacks.
Apache Hadoop 0.23.0 through 0.23.11, and 2.0.0 through 2.5.1 are vulnerable.
Apache Hadoop is prone to an information-disclosure vulnerability.
An attacker can exploit this issue by creating a symlink to a local file and gain access to sensitive information that may lead to further attacks.
Apache Hadoop 0.23.0 through 0.23.11, and 2.0.0 through 2.5.1 are vulnerable.
Solution / Fix
Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Hadoop CVE-2014-3627 Information Disclosure Vulnerability
References:
References:
- Apache Hadoop Homepage (Hadoop)
- Symlinks to peer distributed cache files no longer work (Apache Software Foundation)
- CVE-2014-3627 hadoop: file disclosure flaw (Bugzilla)