Vulnerabilities > Apache > Hadoop > 2.4.0

DATE CVE VULNERABILITY TITLE RISK
2017-04-26 CVE-2017-3161 Cross-site Scripting vulnerability in Apache Hadoop
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.
network
low complexity
apache CWE-79
6.1
2017-04-11 CVE-2016-6811 Permissions, Privileges, and Access Controls vulnerability in Apache Hadoop
In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
network
low complexity
apache CWE-264
8.8
2017-03-23 CVE-2014-0229 Permissions, Privileges, and Access Controls vulnerability in multiple products
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
network
low complexity
cloudera apache CWE-264
4.0
2016-01-02 CVE-2015-7430 Permissions, Privileges, and Access Controls vulnerability in Apache Hadoop
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecified vectors.
local
low complexity
apache CWE-264
4.6