Information Exposure Affecting org.apache.hadoop:hadoop-hdfs package, versions [2.8.0, 2.8.4) [2.9.0, 2.9.1) [3.0.0-alpha1, 3.0.1)
Threat Intelligence
EPSS
0.07% (33rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHEHADOOP-461002
- published 8 Feb 2019
- disclosed 7 Feb 2019
- credit Rushabh Shah
Introduced: 7 Feb 2019
CVE-2018-1296 Open this link in a new tabHow to fix?
Upgrade org.apache.hadoop:hadoop-hdfs
to version 2.8.4, 2.9.1, 3.0.1 or higher.
Overview
org.apache.hadoop:hadoop-hdfs is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.
Affected versions of this package are vulnerable to Information Exposure. The package exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.
CVSS Scores
version 3.1