https://seclists.org/oss-sec/2024/q3/269: CVE-2024-23454: Apache Hadoop: Temporary File Local Information Disclosu
Published Sep 25, 2024
·Updated
Affected Software
1 affected component
Apache Hadoop<3.4.0
Frequently Asked Questions
1
What is the severity of CVE-2024-23454?
The severity of CVE-2024-23454 is classified as low.
2
Which versions of Apache Hadoop are affected by CVE-2024-23454?
CVE-2024-23454 affects all versions of Apache Hadoop before 3.4.0.
3
What is the main issue described in CVE-2024-23454?
CVE-2024-23454 describes a local information disclosure vulnerability due to inappropriate permissions on temporary directories.
4
How do I fix CVE-2024-23454?
To fix CVE-2024-23454, upgrade to Apache Hadoop version 3.4.0 or later where the issue is addressed.
5
What happens if sensitive data is exposed due to CVE-2024-23454?
If sensitive data is exposed due to CVE-2024-23454, other local users may gain unauthorized access to this information.