CVE-2015-1776

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:hadoop:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:hadoop:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:hadoop:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:hadoop:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:hadoop:2.6.4:*:*:*:*:*:*:*

History

21 Nov 2024, 02:26

Type Values Removed Values Added
References () http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA%40mail.gmail.com%3E - () http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA%40mail.gmail.com%3E -
References () http://www.securityfocus.com/bid/83259 - () http://www.securityfocus.com/bid/83259 -

07 Nov 2023, 02:24

Type Values Removed Values Added
References
  • {'url': 'http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA@mail.gmail.com%3E', 'name': '[hadoop-general] 20160215 CVE-2015-1776: Apache Hadoop MapReduce, disclosure of encrypted data', 'tags': [], 'refsource': 'MLIST'}
  • () http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA%40mail.gmail.com%3E -

Information

Published : 2016-04-19 21:59

Updated : 2024-11-21 02:26


NVD link : CVE-2015-1776

Mitre link : CVE-2015-1776

CVE.ORG link : CVE-2015-1776


JSON object : View

Products Affected

apache

  • hadoop
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor