Back

HIGH

hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file

Published Nov 13, 2018

Description

Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of rhs-hadoop as shipped with Red Hat Gluster Storage 3. For JBoss Fuse 6.3 and 7 standalone, while they ship vulnerable artifact via camel-hbase, camel-hdfs2 (fuse 6.3) and camel-hdfs2 (fuse 7), there's no invocation on the flawed code that could lead to an unzip operation. So fuse 6.3, 7 standalone are not affected. However FIS 2.0 and Fuse 7 on OpenShift ship vulnerable artifact via maven BOM, so setting fuse as affected for this reason.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Nov 13, 2018
Updated Aug 5, 2024
Reserved Mar 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 5, 2018
GHSA-6X48-J4X4-CQW3