QID 730714

QID 730714: Apache Hadoop Command Injection Vulnerability

The Apache Hadoop software library is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.

Apache Hadoop's FileUtil.unTar file API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands.

Affected Version:
Hadoop Version from 2.0.0 to 2.10.1
Hadoop Version from 3.0.0-alpha to 3.2.3
Hadoop Version from 3.3.0 to 3.3.2
QID Detection Logic
Unauthenticated Detection: This QID matches the versions of vulnerable Apache Hadoop by querying jmx?qry=Hadoop:service=NameNode,name=NameNodeInfo

A successful exploit may allow an attacker to inject arbitrary commands.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apache security advisory Apache Hadoop for updates and patch information.

    CVEs related to QID 730714

    Software Advisories
    Advisory ID Software Component Link
    Apache Hadoop URL Logo lists.apache.org/thread/mxqnb39jfrwgs3j6phwvlrfq4mlox130