Open mend-bolt-for-github[bot] opened 2 years ago
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
CVE-2017-15713 - Medium Severity Vulnerability
Vulnerable Library - hadoop-common-2.6.0.jar
Apache Hadoop Common
Library home page: http://www.apache.org
Path to dependency file: /tensorflow/java/maven/spark-tensorflow-connector/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/hadoop/hadoop-common/2.6.0/hadoop-common-2.6.0.jar,/tory/org/apache/hadoop/hadoop-common/2.6.0/hadoop-common-2.6.0.jar
Dependency Hierarchy: - :x: **hadoop-common-2.6.0.jar** (Vulnerable Library)
Found in HEAD commit: 1f65fd168afc52c040a47230bb3cb902f7223124
Found in base branch: master
Vulnerability Details
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Publish Date: 2018-01-19
URL: CVE-2017-15713
CVSS 3 Score Details (6.5)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: None - Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://lists.apache.org/thread.html/a790a251ace7213bde9f69777dedb453b1a01a6d18289c14a61d4f91@%3Cgeneral.hadoop.apache.org%3E
Release Date: 2018-01-19
Fix Resolution: 2.8.3
Step up your Open Source Security Game with Mend here