QID 377603
Date Published: 2022-09-26
QID 377603: Apache Hadoop Command Injection Vulnerability
The Apache Hadoop software library is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.
Apache Hadoop's FileUtil.unTar file API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands.
Affected Version:
Hadoop Version from 2.0.0 to 2.10.1
Hadoop Version from 3.0.0-alpha to 3.2.3
Hadoop Version from 3.3.0 to 3.3.2
QID Detection Logic
Authenticated Detection : This QID matches the versions of vulnerable Apache Hadoop installations by launching a Hadoop version request.
Unauthenticated Detection: This QID matches the versions of vulnerable Apache Hadoop by querying jmx?qry=Hadoop:service=NameNode,name=NameNodeInfo
A successful exploit may allow an attacker to inject arbitrary commands.
- Apache Hadoop -
lists.apache.org/thread/mxqnb39jfrwgs3j6phwvlrfq4mlox130
CVEs related to QID 377603
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Hadoop |
|