{"id":"CVE-2017-3166","description":"In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.","cvssScore":7.8,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.0","score":7.8,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":4.6,"vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-732"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2017-11-13","lastModified":"2026-06-17","affectedProducts":[{"vendor":"apache","product":"hadoop","version":"2.6.1"},{"vendor":"apache","product":"hadoop","version":"2.6.2"},{"vendor":"apache","product":"hadoop","version":"2.6.3"},{"vendor":"apache","product":"hadoop","version":"2.6.4"},{"vendor":"apache","product":"hadoop","version":"2.6.5"},{"vendor":"apache","product":"hadoop","version":"2.7.0"},{"vendor":"apache","product":"hadoop","version":"2.7.1"},{"vendor":"apache","product":"hadoop","version":"2.7.2"},{"vendor":"apache","product":"hadoop","version":"2.7.3"},{"vendor":"apache","product":"hadoop","version":"3.0.0","update":"alpha1"}],"totalAffectedProducts":1,"references":[{"url":"https://github.com/advisories/GHSA-99qr-9cc9-fv2x","source":"osv","tags":["ADVISORY"]},{"url":"https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f@%3Cgeneral.hadoop.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/2e16689b44bdd1976b6368c143a4017fc7159d1f2d02a5d54fe9310f%40%3Cgeneral.hadoop.apache.org%3E","source":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E","source":"security@apache.org"}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.hadoop:hadoop-main"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.hadoop:hadoop-main). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"affectedProducts":[{"vendor":"apache","product":"hadoop","isKnown":false,"cpe":"cpe:2.3:a:apache:hadoop:2.6.1:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.apache.hadoop:hadoop-main","introduced":"0","fixed":"2.7.3"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.00323,"percentile":0.25207},"ssvc":{"available":false}}