Miggo Logo

CVE-2017-3166: Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main

7.8

CVSS Score
3.0

Basic Information

EPSS Score
0.44094%
Published
12/21/2018
Updated
1/9/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.hadoop:hadoop-mainmaven< 2.7.32.7.3

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability stems from YARN's file localization preserving original HDFS permissions instead of applying secure defaults. The identified functions are core components of the localization process where:

  1. LocalCacheProtocolImpl.download() would handle the actual file transfer from HDFS to local FS
  2. LocalizedResource.localize() coordinates the localization workflow Without seeing the actual patch, these are the most likely candidates based on the vulnerability pattern (CWE-732) and Hadoop architecture. The medium confidence reflects the need to infer implementation details from vulnerability description rather than explicit patch evidence.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

In *p**** ***oop v*rsions *.*.* to *.*.*, *.*.* to *.*.*, *n* *.*.*-*lp***, i* * *il* in *n *n*ryption zon* wit* ****ss p*rmissions t**t m*k* it worl* r*****l* is lo**liz** vi* Y*RN's lo**liz*tion m****nism, t**t *il* will ** stor** in * worl*-r*****

Reasoning

T** vuln*r**ility st*ms *rom Y*RN's *il* lo**liz*tion pr*s*rvin* ori*in*l ***S p*rmissions inst*** o* *pplyin* s**ur* ****ults. T** i**nti*i** *un*tions *r* *or* *ompon*nts o* t** lo**liz*tion pro**ss w**r*: *. Lo**l*****Proto*olImpl.*ownlo**() woul