Exposure of Sensitive Information to an Unauthorized Actor in Hadoop
High severity
GitHub Reviewed
Published
Feb 12, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 2.7.6
>= 2.8.0, < 2.8.4
= 2.9.0
Patched versions
2.7.6
2.8.4
2.9.1
Description
Published to the GitHub Advisory Database
Feb 12, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.
References