Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
Moderate severity
GitHub Reviewed
Published
Dec 21, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 2.7.5
>= 2.8.0, < 2.8.3
Patched versions
2.7.5
2.8.3
Description
Published to the GitHub Advisory Database
Dec 21, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
References