« Volver al listado

CVE-2018-1296

Estado: ModificadaAlta (7.5)—

In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-1296",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Hadoop",
          "versions": [
            {
              "status": "affected",
              "version": "Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, 2.5.0 to 2.7.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-02-07T22:29:00.240",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/106764",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/a5b15bc76fbdad2ee40761aacf954a13aeef67e305f86d483f267e8e%40%3Cuser.hadoop.apache.org%3E",
      "source": "security@apache.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/106764",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/a5b15bc76fbdad2ee40761aacf954a13aeef67e305f86d483f267e8e%40%3Cuser.hadoop.apache.org%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent."
    },
    {
      "lang": "es",
      "value": "En Apache Hadoop, desde la versión 3.0.0-alpha1 hasta la 3.0.0, 2.9.0, desde la 2.8.0 hasta la 2.8.3 y desde la 2.5.0 hasta la 2.7.5, HDFS expone pares de atributos de valor/clave extendidos durante listXAttrs, verificando solo el acceso de búsqueda a nivel de ruta al directorio en lugar de los permisos de lectura a nivel de ruta al referente."
    }
  ],
  "lastModified": "2026-06-17T01:50:56.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "330DD938-7CFA-4890-B9F1-2A9D9DDB9C4C",
              "versionEndIncluding": "2.7.5",
              "versionStartIncluding": "2.5.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6E67A08-33CB-49FF-ACD9-96FD47139B1F"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D430A9EF-5A77-4E47-9A64-E64FEA243B87"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFC32FB7-9A23-45F3-87FE-ADFB3EEEE574"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D221DB4-DEBC-4DF3-8ADB-2996C00F01D8"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:2.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AA8A5A7-0E96-4661-AE60-BA54C82991EA"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E486028-681D-4B3E-95F6-CE42CDA88A08"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:3.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C33530ED-6093-4B4C-AFDB-4DB5EB5878E0"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:3.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38BCF20D-169E-4847-8880-A223467B8639"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:3.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "336DADCF-3302-423D-BFDC-72C031AD1CAD"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:3.0.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "689B619C-04C4-43C6-B103-DDAAA9C9CC9C"
            },
            {
              "criteria": "cpe:2.3:a:apache:hadoop:3.0.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E457B6F-5F01-45C5-8568-7AF598721AEB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}