Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-23454

Apache Hadoop: RunJar temporary directory readable by other local users

Technology

Apache Hadoop

CVSS Score

6.2 / 10.0

Affected Versions

before 3.4.0

Upstream Fix

3.4.0

Published

September 25, 2024

OSSeva Coverage

Fixed upstream

Description

RunJar.run() does not set permissions on its temporary directory by default. On Unix-like systems the system temporary directory is shared, so other local users may be able to read sensitive data written there. Apache rates it low. It is tracked as HADOOP-19031 and was announced on the general@hadoop list rather than the Hadoop CVE page. The 6.2 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running before 3.4.0, you need this patch. Book a discovery call to get covered.