CVE-2017-3166
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.
En Apache Hadoop, en versiones 2.6.1 a 2.6.5, 2.7.0 a 2.7.3 y 3.0.0-alpha1, si un archivo en una zona de cifrado con permisos de acceso que lo hacen legible para todos los usuarios se localiza mediante el mecanismo de localización de YARN, ese archivo será almacenado en una localización legible por todos los usuarios y puede ser compartido libremente con cualquier aplicación que solicite localizar ese archivo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-05 CVE Reserved
- 2017-11-13 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.6.1 Search vendor "Apache" for product "Hadoop" and version "2.6.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.6.2 Search vendor "Apache" for product "Hadoop" and version "2.6.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.6.3 Search vendor "Apache" for product "Hadoop" and version "2.6.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.6.4 Search vendor "Apache" for product "Hadoop" and version "2.6.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.6.5 Search vendor "Apache" for product "Hadoop" and version "2.6.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.7.0 Search vendor "Apache" for product "Hadoop" and version "2.7.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.7.1 Search vendor "Apache" for product "Hadoop" and version "2.7.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.7.2 Search vendor "Apache" for product "Hadoop" and version "2.7.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.7.3 Search vendor "Apache" for product "Hadoop" and version "2.7.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 3.0.0 Search vendor "Apache" for product "Hadoop" and version "3.0.0" | alpha1 |
Affected
|