QID 730714
QID 730714: Apache Hadoop Command Injection Vulnerability
The Apache Hadoop software library is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.
Apache Hadoop's FileUtil.unTar file API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands.
Affected Version:
Hadoop Version from 2.0.0 to 2.10.1
Hadoop Version from 3.0.0-alpha to 3.2.3
Hadoop Version from 3.3.0 to 3.3.2
QID Detection Logic
Unauthenticated Detection: This QID matches the versions of vulnerable Apache Hadoop by querying jmx?qry=Hadoop:service=NameNode,name=NameNodeInfo
A successful exploit may allow an attacker to inject arbitrary commands.
Solution
Refer to Apache security advisory Apache Hadoop for updates and patch information.
Vendor References
- Apache Hadoop -
lists.apache.org/thread/mxqnb39jfrwgs3j6phwvlrfq4mlox130
CVEs related to QID 730714
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Hadoop |
|