VYPR
High severity7.8NVD Advisory· Published Nov 13, 2017· Updated May 13, 2026

CVE-2017-3166

CVE-2017-3166

Description

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.hadoop:hadoop-mainMaven
< 2.7.32.7.3

Affected products

11
  • Apache/Hadoop10 versions
    cpe:2.3:a:apache:hadoop:2.6.1:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:apache:hadoop:2.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:2.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:hadoop:3.0.0:alpha1:*:*:*:*:*:*
  • Apache Software Foundation/Apache Hadoopv5
    Range: 2.6.1 to 2.6.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.