CVE-2017-3162: Input Validation
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3162?
CVE-2017-3162 has been classified with a moderate severity due to the lack of query parameter validation in Apache Hadoop.
Who is affected by CVE-2017-3162?
CVE-2017-3162 affects users of Apache Hadoop versions up to 2.6.5 that utilize HDFS clients to interact with DataNode servlets.
How do I fix CVE-2017-3162?
To mitigate CVE-2017-3162, upgrade to Apache Hadoop version 2.7.0 or later, where the vulnerability has been addressed.
What type of vulnerability is CVE-2017-3162?
CVE-2017-3162 is classified as a security vulnerability related to improper input validation in the DataNode servlet.
What operational impact does CVE-2017-3162 have?
CVE-2017-3162 could potentially allow unauthorized access to the HDFS namespace, impacting confidentiality and integrity.