CVE-2017-3161: XSS
Published Apr 26, 2017
·Updated
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.
Affected Software
1 affected component
Apache Hadoop<=2.6.5
Event History
Apr 26, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3161?
CVE-2017-3161 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-3161?
To fix CVE-2017-3161, you should upgrade Apache Hadoop to version 2.7.0 or higher.
3
What software versions are affected by CVE-2017-3161?
CVE-2017-3161 affects Apache Hadoop versions prior to 2.7.0, specifically up to 2.6.5.
4
What type of attack does CVE-2017-3161 allow?
CVE-2017-3161 allows attackers to perform cross-site scripting (XSS) attacks via unescaped query parameters.
5
Is CVE-2017-3161 a known vulnerability?
Yes, CVE-2017-3161 is a publicly known vulnerability reported in Apache Hadoop.