QID 981337
QID 981337: Java (maven) Security Update for org.apache.hadoop:hadoop-main (GHSA-3v44-382q-55f4)
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3v44-382q-55f4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-3v44-382q-55f4 -
github.com/advisories/GHSA-3v44-382q-55f4
CVEs related to QID 981337
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3v44-382q-55f4 | org.apache.hadoop:hadoop-main |
|