OESA-2024-2349

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-2349
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2024-2349.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2024-2349
Upstream
Published
2024-11-08T01:36:45Z
Modified
2025-09-03T06:20:01.696428Z
Summary
hadoop security update
Details

Apache Hadoop is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage.

Security Fix(es):

Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local users may be able to view the content. This is because, on unix-like systems, the system temporary directory is shared between all local users. As such, files written in this directory, without setting the correct posix permissions explicitly, may be viewable by all other local users.(CVE-2024-23454)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP3 / hadoop

Package

Name
hadoop
Purl
pkg:rpm/openEuler/hadoop&distro=openEuler-22.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.6-4.oe2203sp3

Ecosystem specific

{
    "noarch": [
        "hadoop-client-3.3.6-4.oe2203sp3.noarch.rpm",
        "hadoop-common-3.3.6-4.oe2203sp3.noarch.rpm",
        "hadoop-hdfs-3.3.6-4.oe2203sp3.noarch.rpm",
        "hadoop-httpfs-3.3.6-4.oe2203sp3.noarch.rpm",
        "hadoop-mapreduce-3.3.6-4.oe2203sp3.noarch.rpm",
        "hadoop-mapreduce-examples-3.3.6-4.oe2203sp3.noarch.rpm",
        "hadoop-maven-plugin-3.3.6-4.oe2203sp3.noarch.rpm",
        "hadoop-tests-3.3.6-4.oe2203sp3.noarch.rpm"
    ],
    "aarch64": [
        "hadoop-common-native-3.3.6-4.oe2203sp3.aarch64.rpm",
        "hadoop-debuginfo-3.3.6-4.oe2203sp3.aarch64.rpm",
        "hadoop-debugsource-3.3.6-4.oe2203sp3.aarch64.rpm",
        "hadoop-devel-3.3.6-4.oe2203sp3.aarch64.rpm",
        "hadoop-yarn-3.3.6-4.oe2203sp3.aarch64.rpm",
        "hadoop-yarn-security-3.3.6-4.oe2203sp3.aarch64.rpm",
        "libhdfs-3.3.6-4.oe2203sp3.aarch64.rpm"
    ],
    "x86_64": [
        "hadoop-common-native-3.3.6-4.oe2203sp3.x86_64.rpm",
        "hadoop-debuginfo-3.3.6-4.oe2203sp3.x86_64.rpm",
        "hadoop-debugsource-3.3.6-4.oe2203sp3.x86_64.rpm",
        "hadoop-devel-3.3.6-4.oe2203sp3.x86_64.rpm",
        "hadoop-yarn-3.3.6-4.oe2203sp3.x86_64.rpm",
        "hadoop-yarn-security-3.3.6-4.oe2203sp3.x86_64.rpm",
        "libhdfs-3.3.6-4.oe2203sp3.x86_64.rpm"
    ],
    "src": [
        "hadoop-3.3.6-4.oe2203sp3.src.rpm"
    ]
}