Information Exposure Affecting org.apache.hadoop:hadoop-hdfs package, versions [2.8.0, 2.8.4) [2.9.0, 2.9.1) [3.0.0-alpha1, 3.0.1)


0.0
medium

Snyk CVSS

    Attack Complexity High

    Threat Intelligence

    EPSS 0.07% (31st percentile)
Expand this section
NVD
7.5 high
Expand this section
Red Hat
5.9 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGAPACHEHADOOP-461002
  • published 8 Feb 2019
  • disclosed 7 Feb 2019
  • credit Rushabh Shah

How to fix?

Upgrade org.apache.hadoop:hadoop-hdfs to version 2.8.4, 2.9.1, 3.0.1 or higher.

Overview

org.apache.hadoop:hadoop-hdfs is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.

Affected versions of this package are vulnerable to Information Exposure. The package exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.