7.5

CVE-2018-1296

In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHadoop Version >= 2.5.0 <= 2.7.5
ApacheHadoop Version2.8.0
ApacheHadoop Version2.8.1
ApacheHadoop Version2.8.2
ApacheHadoop Version2.8.3
ApacheHadoop Version2.9.0
ApacheHadoop Version3.0.0
ApacheHadoop Version3.0.0 Updatealpha1
ApacheHadoop Version3.0.0 Updatealpha2
ApacheHadoop Version3.0.0 Updatealpha3
ApacheHadoop Version3.0.0 Updatealpha4
ApacheHadoop Version3.0.0 Updatebeta1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.677
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.