/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-gfpx-rg68-qm9p

Published

Last updated

https://images.chainguard.dev/security/CGA-gfpx-rg68-qm9p
Package

hadoop-fips-3.3.6

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2016-5001
  • GHSA-8r28-r8cp-g6cp

Severity

Unknown

Summary

Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop

Description

This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs