CVE-2016-5393: High severity apache hadoop vulnerability
Published Nov 29, 2016
·Updated
In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
Affected Software
8 affected components
Apache Hadoop=2.7.0
Apache Hadoop=2.7.1
Apache Hadoop=2.7.2
Apache Hadoop=2.6.0
Apache Hadoop=2.6.1
Apache Hadoop=2.6.2
Apache Hadoop=2.6.3
Apache Hadoop=2.6.4
Event History
Nov 29, 2016
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5393?
CVE-2016-5393 is considered a critical vulnerability due to the potential for remote users to execute arbitrary commands with HDFS service privileges.
2
How do I fix CVE-2016-5393?
To fix CVE-2016-5393, upgrade Apache Hadoop to version 2.6.5, 2.7.3, or later.
3
Which versions of Apache Hadoop are affected by CVE-2016-5393?
CVE-2016-5393 affects Apache Hadoop versions 2.6.x before 2.6.5 and 2.7.x before 2.7.3.
4
What are the risks associated with CVE-2016-5393?
The risks associated with CVE-2016-5393 include unauthorized access to system privileges and potential compromise of the HDFS environment.
5
Can CVE-2016-5393 be exploited remotely?
Yes, CVE-2016-5393 can be exploited remotely by authenticated users of the HDFS NameNode.