VYPR
Medium severity6.5NVD Advisory· Published Jan 19, 2018· Updated Jun 17, 2026

CVE-2017-15713

CVE-2017-15713

Description

Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.hadoop:hadoop-mainMaven
< 2.7.52.7.5
org.apache.hadoop:hadoop-mainMaven
>= 2.8.0, < 2.8.32.8.3

Affected products

17
  • Apache/Hadoop15 versions
    cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:*range: >=0.23.0,<=0.23.11
    • cpe:2.3:a:apache:hadoop:2.0.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.0.1:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.0.2:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.0.3:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.0.4:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.0.5:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.0.6:alpha:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.1.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.1.1:beta:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:3.0.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:3.0.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:3.0.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:3.0.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:3.0.0:beta1:*:*:*:*:*:*
  • Apache Software Foundation/Apache Hadoopv5
    Range: 0.23.0 to 0.23.11

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.