Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-23454
Apache Hadoop: RunJar temporary directory readable by other local users
Technology
Apache Hadoop
CVSS Score
6.2 / 10.0
Affected Versions
before 3.4.0
Upstream Fix
3.4.0
Published
September 25, 2024
OSSeva Coverage
Fixed upstream
Description
RunJar.run() does not set permissions on its temporary directory by default. On Unix-like systems the system temporary directory is shared, so other local users may be able to read sensitive data written there. Apache rates it low. It is tracked as HADOOP-19031 and was announced on the general@hadoop list rather than the Hadoop CVE page. The 6.2 score on NVD is from CISA-ADP.
Is your Apache Hadoop deployment affected?
If you're running before 3.4.0, you need this patch. Book a discovery call to get covered.