SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 64030: SASHDAT files saved to Hadoop Distributed File System (HDFS) grant Read and Write access to all users if you do not specify custom permissions

DetailsHotfixAboutRate It

Severity: High

Description: When using the SAS® 9.4 SASHDAT engine or SAS® Viya® Cloud Analytic Services (CAS) actions to save files to HDFS in SASHDAT format, you encounter a security vulnerability. In this scenario, permissions on saved SASHDAT files incorrectly default to 666 (Read and Write access for all) when you do not specify a permission setting. Instead, the behavior when you do not specify permissions should be that the default HDFS umask is applied to the file. The default HDFS unmask is generally derived from hdfs-site.xml settings such as dfs.umaskmode or fs.permissions.umask-mode.

Potential Impact: SASHDAT files can be read, modified, or deleted by any user with access to the HDFS directory that contains these files.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS LASR Analytic ServerLinux for x642.829.4 TS1M6
SAS SystemSAS ViyaLinux for x643.4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.