Apache Hadoop security advisories
12 advisories · none critical or high in 12 months · latest Sep 25, 2024
12 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 252024 | Apache Hadoop: Temporary File Local Information Disclosure CVE-2024-23454Low3.3fixed in 3.4.0 | Low3.3 | 3.4.0 |
| Aug 52022 | Apache Hadoop argument injection vulnerability CVE-2022-25168Critical9.8fixed in 2.10.2, 3.2.4, 3.3.3 | Critical9.8 | 2.10.2, 3.2.4, 3.3.3 |
| Jun 142022 | Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2 CVE-2021-37404Critical9.8fixed in 2.10.2, 3.2.3, 3.3.2 | Critical9.8 | 2.10.2, 3.2.3, 3.3.2 |
| May 172022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop CVE-2015-1776Medium6.2fixed in 2.6.5 | Medium6.2 | 2.6.5 |
| May 172022 | Improper Access Control in Apache Hadoop CVE-2016-5393High8.8fixed in 2.6.5, 2.7.3 | High8.8 | 2.6.5, 2.7.3 |
| May 172022 | Improper Authentication in Apache Hadoop CVE-2013-2192Lowfixed in 0.23.9, 2.0.6-alpha | Low | 0.23.9, 2.0.6-alpha |
| May 172022 | Improper Authentication in Apache Hadoop CVE-2014-0229Medium6.5fixed in 0.23.11, 2.4.1 | Medium6.5 | 0.23.11, 2.4.1 |
| May 172022 | Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation CVE-2017-7669High7.5fixed in 2.8.1, 3.0.0-alpha3 | High7.5 | 2.8.1, 3.0.0-alpha3 |
| May 142022 | Insecure Inherited Permissions in Apache Hadoop CVE-2016-6811High8.8fixed in 2.7.4 | High8.8 | 2.7.4 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop CVE-2016-5001Medium5.5fixed in 2.6.4, 2.7.2 | Medium5.5 | 2.6.4, 2.7.2 |
| Apr 82022 | Path traversal in Hadoop CVE-2022-26612Critical9.8fixed in 2.10.2, 3.2.3, 3.3.3 | Critical9.8 | 2.10.2, 3.2.3, 3.3.3 |
| Feb 92022 | Improper Privilege Management in Apache Hadoop CVE-2020-9492High8.8fixed in 2.10.1, 3.1.4, 3.2.2 | High8.8 | 2.10.1, 3.1.4, 3.2.2 |
About Apache Hadoop
Distributed storage and processing.
Packages watched: org.apache.hadoop:hadoop-common (Maven).