CVE-2017-15713
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
19/01/2018
Last modified:
07/11/2023
Description
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* | 0.23.0 (including) | 0.23.11 (including) |
| cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* | 2.2.0 (including) | 2.8.2 (including) |
| cpe:2.3:a:apache:hadoop:2.0.0:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.0.1:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.0.2:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.0.3:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.0.4:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.0.5:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.0.6:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.1.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:2.1.1:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:3.0.0:alpha1:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:3.0.0:alpha2:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:3.0.0:alpha3:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hadoop:3.0.0:alpha4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



