Known Vulnerabilities for Hadoop by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Hadoop" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-25168 | Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attac... | 9.8 - CRITICAL | 2022-08-04 | 2023-06-26 |
| CVE-2021-37404 | There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without ... | 9.8 - CRITICAL | 2022-06-13 | 2023-06-27 |
| CVE-2021-33036 | In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn ... | 8.8 - HIGH | 2022-06-15 | 2022-10-27 |
| CVE-2021-25642 | ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooK... | 8.8 - HIGH | 2022-08-25 | 2023-02-10 |
| CVE-2020-9492 | In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authoriza... | 8.8 - HIGH | 2021-01-26 | 2023-11-07 |
| CVE-2019-17195 | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an ap... | 9.8 - CRITICAL | 2019-10-15 | 2023-11-07 |
| CVE-2018-11764 | Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may im... | 8.8 - HIGH | 2020-10-21 | 2022-06-03 |
| CVE-2018-8029 | In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can... | 8.8 - HIGH | 2019-05-30 | 2023-11-07 |
| CVE-2018-8009 | Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploit... | 8.8 - HIGH | 2018-11-13 | 2023-11-07 |
| CVE-2018-1296 | In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value ... | 7.5 - HIGH | 2019-02-07 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Hadoop | 3.3.0 | rc0 | All | All |
| Application | Apache | Hadoop | 3.2.2 | - | All | All |
| Application | Apache | Hadoop | 3.2.2 | rc0 | All | All |
| Application | Apache | Hadoop | 3.2.2 | rc1 | All | All |
| Application | Apache | Hadoop | 3.2.2 | rc2 | All | All |
| Application | Apache | Hadoop | 3.2.2 | rc3 | All | All |
| Application | Apache | Hadoop | 3.2.2 | rc4 | All | All |
| Application | Apache | Hadoop | 3.2.2 | rc5 | All | All |
| Application | Apache | Hadoop | 3.2.1 | rc0 | All | All |
| Application | Apache | Hadoop | 3.2.0 | All | All | All |
| Application | Apache | Hadoop | 3.2.0 | - | All | All |
| Application | Apache | Hadoop | 3.2.0 | rc0 | All | All |
| Application | Apache | Hadoop | 3.2.0 | rc1 | All | All |
| Application | Apache | Hadoop | 3.1.4 | - | All | All |
| Application | Apache | Hadoop | 3.1.4 | rc0 | All | All |
| Application | Apache | Hadoop | 3.1.4 | rc1 | All | All |
| Application | Apache | Hadoop | 3.1.4 | rc2 | All | All |
| Application | Apache | Hadoop | 3.1.4 | rc3 | All | All |
| Application | Apache | Hadoop | 3.1.4 | rc4 | All | All |
| Application | Apache | Hadoop | 3.1.3 | - | All | All |