Hadoop HDFSBrowser 信息泄露

基本字段

漏洞编号:
SSV-93037
披露/发现时间:
2017-04-25
提交时间:
2017-04-24
漏洞等级:
漏洞类别:
信息泄漏
影响组件:
Hadoop
漏洞作者:
未知
提交者:
Knownsec
CVE-ID:
补充
CNNVD-ID:
补充
CNVD-ID:
补充
ZoomEye Dork:
补充

来源

漏洞详情

贡献者 共获得  0KB

Browsing the HDFS datalake

Description

There are 2 different and distinct approaches to browse the HDFS datalake: A. Through the WebHDFS API B. Through the native Hadoop CLI

WebHDFS

WebHDFS offers REST API for users to access data on the HDFS filesystem using the HTTP protocol. The activation of this feature is configured on the cluster side through the following directive in the hdfs-site.xml file:

dfs.webhdfs.enabled: true|false Enable WebHDFS (REST API) in Namenodes and Datanodes.

The API allows to perform all possible actions on the HDFS filesystem (view, create, modify, etc.).

By default, if Kerberos authentication is not enabled, no credential is needed to request these services: only user identification is needed using the user.name parameter. WebHDFS API are exposed on the following services:

DataNode HDFS DataNode WebUI on port 50075
Third-party HttpFS module on port 14000

Another possible method to list the content is to call the /listPaths/ URI on a NameNode WebUI on port 50070 which returns an XML file.

共 0  兑换了

PoC (pocsuite 插件) (pocsuite 插件)

贡献者 匿名 共获得   8KB
登陆后兑换查看

isqlmap 天机 None Luisa 共 4 兑换

参考链接

解决方案

临时解决方案

暂无临时解决方案

官方解决方案

暂无官方解决方案

防护方案

暂无防护方案

人气 2805
评论前需绑定手机 现在绑定

暂无评论

※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负