{"id":"GHSA-3v44-382q-55f4","summary":"Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main","details":"Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.","aliases":["CVE-2017-15713"],"modified":"2023-11-08T03:58:58.547397Z","published":"2018-12-21T17:50:13Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T20:56:25Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15713"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3v44-382q-55f4"},{"type":"WEB","url":"https://lists.apache.org/thread.html/a790a251ace7213bde9f69777dedb453b1a01a6d18289c14a61d4f91@%3Cgeneral.hadoop.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.hadoop:hadoop-main","ecosystem":"Maven","purl":"pkg:maven/org.apache.hadoop/hadoop-main"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.5"}]}],"versions":["0.23.1","0.23.10","0.23.11","0.23.3","0.23.4","0.23.5","0.23.6","0.23.7","0.23.8","0.23.9","2.0.0-alpha","2.0.1-alpha","2.0.2-alpha","2.0.3-alpha","2.0.4-alpha","2.0.5-alpha","2.0.6-alpha","2.1.0-beta","2.1.1-beta","2.2.0","2.3.0","2.4.0","2.4.1","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-3v44-382q-55f4/GHSA-3v44-382q-55f4.json"}},{"package":{"name":"org.apache.hadoop:hadoop-main","ecosystem":"Maven","purl":"pkg:maven/org.apache.hadoop/hadoop-main"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.3"}]}],"versions":["2.8.0","2.8.1","2.8.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-3v44-382q-55f4/GHSA-3v44-382q-55f4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}