[ 
https://issues.apache.org/jira/browse/HADOOP-19031?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Steve Loughran updated HADOOP-19031:
------------------------------------
    Description: 

Apache Hadoop’s RunJar.run() does not set permissions for temporary directory 
by default. If sensitive data will be present in this file, all the other local 
users may be able to view the content.
This is because, on unix-like systems, the system temporary directory is
shared between all local users. As such, files written in this directory,
without setting the correct posix permissions explicitly, may be viewable
by all other local users.

Andrea Cosentino (finder)

> CVE-2024-23454: Apache Hadoop: Temporary File Local Information Disclosure
> --------------------------------------------------------------------------
>
>                 Key: HADOOP-19031
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19031
>             Project: Hadoop Common
>          Issue Type: Bug
>          Components: security
>    Affects Versions: 3.4.0, 3.5.0
>            Reporter: Xiaoqiao He
>            Assignee: Xiaoqiao He
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 3.4.0, 3.5.0
>
>
> Apache Hadoop’s RunJar.run() does not set permissions for temporary directory 
> by default. If sensitive data will be present in this file, all the other 
> local users may be able to view the content.
> This is because, on unix-like systems, the system temporary directory is
> shared between all local users. As such, files written in this directory,
> without setting the correct posix permissions explicitly, may be viewable
> by all other local users.
> Andrea Cosentino (finder)



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to