Known Vulnerabilities for Hadoop by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Hadoop" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-26031 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-16 | 2024-01-12 |
| CVE-2022-26612 json | In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other O... | 9.8 - CRITICAL | 2022-04-07 | 2023-08-08 |
| CVE-2022-25168 json | Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attac... | 9.8 - CRITICAL | 2022-08-04 | 2023-06-26 |
| CVE-2021-37404 json | There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without ... | 9.8 - CRITICAL | 2022-06-13 | 2023-06-27 |
| CVE-2021-33036 json | In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn ... | 8.8 - HIGH | 2022-06-15 | 2022-10-27 |
| CVE-2021-25642 json | ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooK... | 8.8 - HIGH | 2022-08-25 | 2023-02-10 |
| CVE-2020-9492 json | In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authoriza... | 8.8 - HIGH | 2021-01-26 | 2023-11-07 |
| CVE-2019-17195 json | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an ap... | 9.8 - CRITICAL | 2019-10-15 | 2023-11-07 |
| CVE-2018-11768 json | In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information ... | 7.5 - HIGH | 2019-10-04 | 2023-11-07 |
| CVE-2018-11767 json | In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, ... | 7.4 - HIGH | 2019-03-21 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Hadoop | 3.3.0 | |||
| Application | Apache | Hadoop | 3.2.2 | |||
| Application | Apache | Hadoop | 3.2.2 | |||
| Application | Apache | Hadoop | 3.2.2 | |||
| Application | Apache | Hadoop | 3.2.2 | |||
| Application | Apache | Hadoop | 3.2.2 | |||
| Application | Apache | Hadoop | 3.2.2 | |||
| Application | Apache | Hadoop | 3.2.2 | |||
| Application | Apache | Hadoop | 3.2.1 | |||
| Application | Apache | Hadoop | 3.2.0 | |||
| Application | Apache | Hadoop | 3.2.0 | |||
| Application | Apache | Hadoop | 3.2.0 | |||
| Application | Apache | Hadoop | 3.2.0 | |||
| Application | Apache | Hadoop | 3.1.4 | |||
| Application | Apache | Hadoop | 3.1.4 | |||
| Application | Apache | Hadoop | 3.1.4 | |||
| Application | Apache | Hadoop | 3.1.4 | |||
| Application | Apache | Hadoop | 3.1.4 | |||
| Application | Apache | Hadoop | 3.1.4 | |||
| Application | Apache | Hadoop | 3.1.3 |