CVE-2017-3166
Estado: ModificadaAlta (7.8)—
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.32%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-732
Referencias
- https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f%40%3Cgeneral.hadoop.apache.org%3E
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f%40%3Cgeneral.hadoop.apache.org%3E
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-3166",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache Hadoop",
"versions": [
{
"status": "affected",
"version": "2.6.1 to 2.6.5"
},
{
"status": "affected",
"version": "2.7.0 to 2.7.3"
},
{
"status": "affected",
"version": "3.0.0-alpha1 to 3.0.0-alpha3"
}
]
}
]
}
],
"published": "2017-11-13T14:29:00.870",
"references": [
{
"url": "https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f%40%3Cgeneral.hadoop.apache.org%3E",
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E",
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f%40%3Cgeneral.hadoop.apache.org%3E",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file."
},
{
"lang": "es",
"value": "En Apache Hadoop, en versiones 2.6.1 a 2.6.5, 2.7.0 a 2.7.3 y 3.0.0-alpha1, si un archivo en una zona de cifrado con permisos de acceso que lo hacen legible para todos los usuarios se localiza mediante el mecanismo de localización de YARN, ese archivo será almacenado en una localización legible por todos los usuarios y puede ser compartido libremente con cualquier aplicación que solicite localizar ese archivo."
}
],
"lastModified": "2026-06-17T01:17:39.483",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:hadoop:2.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "569A25D2-6BAE-4AF3-B5A4-E578F5BF4000"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0303DDA4-A5C1-4358-A4DC-F85C1B2E3254"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68F54CBB-0D44-4F8F-A45D-330213E0C349"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.6.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97B60011-6E60-4DBC-957B-C1F1CBB2B777"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.6.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78F6B3B1-8C97-42F4-B5C0-B821B0866D67"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00E1BC92-93DF-479F-8C05-672ADF348565"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0CACFCC5-8A44-4DAE-A83F-139B488509A4"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BE605CB-8A00-45EC-9DAA-775D4E9F5B85"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:2.7.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9437CAB-BAA4-40E1-9A24-2A801AA132F4"
},
{
"criteria": "cpe:2.3:a:apache:hadoop:3.0.0:alpha1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C33530ED-6093-4B4C-AFDB-4DB5EB5878E0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}