Information Exposure Affecting org.apache.hadoop:hadoop-hdfs package, versions [2.8.0, 2.8.4) [2.9.0, 2.9.1) [3.0.0-alpha1, 3.0.1)

  • Attack Complexity


Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id


  • published

    8 Feb 2019

  • disclosed

    7 Feb 2019

  • credit

    Rushabh Shah

How to fix?

Upgrade org.apache.hadoop:hadoop-hdfs to version 2.8.4, 2.9.1, 3.0.1 or higher.


org.apache.hadoop:hadoop-hdfs is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.

Affected versions of this package are vulnerable to Information Exposure. The package exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.