[MAVEN:GHSA-HX83-RPQF-M267] user/group information can be corrupted across storing in fsimage and reading back from fsimage

Severity High
Affected Packages 3
Fixed Packages 3
CVEs 1

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.

Package Affected Version
pkg:maven/org.apache.hadoop/hadoop-main >= 3.0.0, < 3.1.1
pkg:maven/org.apache.hadoop/hadoop-main >= 2.9.0, < 2.9.2
pkg:maven/org.apache.hadoop/hadoop-main >= 2.2.0, < 2.8.5
ID
MAVEN:GHSA-HX83-RPQF-M267
Severity
high
URL
https://github.com/advisories/GHSA-hx83-rpqf-m267
Published
2019-11-20T01:38:00
(4 years ago)
Modified
2023-01-09T05:01:57
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.hadoop/hadoop-main org.apache.hadoop hadoop-main >= 3.0.0 < 3.1.1
Fixed pkg:maven/org.apache.hadoop/hadoop-main org.apache.hadoop hadoop-main = 3.1.1
Affected pkg:maven/org.apache.hadoop/hadoop-main org.apache.hadoop hadoop-main >= 2.9.0 < 2.9.2
Fixed pkg:maven/org.apache.hadoop/hadoop-main org.apache.hadoop hadoop-main = 2.9.2
Affected pkg:maven/org.apache.hadoop/hadoop-main org.apache.hadoop hadoop-main >= 2.2.0 < 2.8.5
Fixed pkg:maven/org.apache.hadoop/hadoop-main org.apache.hadoop hadoop-main = 2.8.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...