« Volver al listado

CVE-2015-1776

Estado: ModificadaMedia (6.2)—

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-1776",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.2,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-04-19T21:59:02.100",
  "references": [
    {
      "url": "http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA%40mail.gmail.com%3E",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/83259",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://mail-archives.apache.org/mod_mbox/hadoop-general/201602.mbox/%3CCAGCyb56CPgQMcxZ7jP87SfM5OKGx+E49DtrzCTQ6+nQf2a4nSA%40mail.gmail.com%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/83259",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensitive information by reading the file."
    },
    {
      "lang": "es",
      "value": "Apache Hadoop 2.6.x cifra los datos intermedios generados por una tarea MapReduce y los almacena junto con la clave de cifrado en un archivo de credenciales en disco cuando la funcionalidad de cifrado de datos Intermediate está habilitada, lo que permite a usuarios locales obtener información sensible mediante la lectura del archivo."
    }
  ],
  "lastModified": "2026-06-17T00:22:58.307",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25EA1A6B-46EF-4157-854A-8991158D8A56"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "569A25D2-6BAE-4AF3-B5A4-E578F5BF4000"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0303DDA4-A5C1-4358-A4DC-F85C1B2E3254"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68F54CBB-0D44-4F8F-A45D-330213E0C349"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97B60011-6E60-4DBC-957B-C1F1CBB2B777"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}