Apache HadoopGHSA-rmpj-7c96-mrg8
Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
Critical9.8CVE-2021-37404 · Published Jun 14, 2022 · updated Feb 22, 2024
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hadoop:hadoop-common Maven | >= 3.3.0, < 3.3.2 | 3.3.2 |
| >= 3.0.0, < 3.2.3 | 3.2.3 | |
| < 2.10.2 | 2.10.2 |
Details and references
More Apache Hadoop advisories
All Apache Hadoop| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop | Medium6.2 | 2.6.5 |
| May 172022 | Improper Access Control in Apache Hadoop | High8.8 | 2.6.5+1 more |
| May 172022 | Improper Authentication in Apache Hadoop | Low | 0.23.9+1 more |
| May 172022 | Improper Authentication in Apache Hadoop | Medium6.5 | 0.23.11+1 more |
| May 172022 | Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation | High7.5 | 2.8.1+1 more |
| May 142022 | Insecure Inherited Permissions in Apache Hadoop | High8.8 | 2.7.4 |