Apache / Hadoop
37 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-27821 | HDFS native client: Out of bounds write in URI parser of native HDFS client | HIGH | 7.3 | Jan 26, 2026 |
| CVE-2024-23454 | Apache Hadoop: Temporary File Local Information Disclosure | LOW | 2.0 | Sep 25, 2024 |
| CVE-2023-26031 | Privilege escalation in Apache Hadoop Yarn container-executor binary on Linux systems | HIGH | 7.7 | Nov 16, 2023 |
| CVE-2021-25642 | Apache Hadoop YARN remote code execution in ZKConfigurationStore of capacity scheduler | HIGH | 8.8 | Aug 25, 2022 |
| CVE-2022-25168 | Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTar | CRITICAL | 9.8 | Aug 4, 2022 |
| CVE-2021-33036 | Apache Hadoop Privilege escalation vulnerability | HIGH | 8.8 | Jun 15, 2022 |
| CVE-2021-37404 | Heap buffer overflow in libhdfs native library | CRITICAL | 9.8 | Jun 13, 2022 |
| CVE-2022-26612 | Arbitrary file write in FileUtil#unpackEntries on Windows | CRITICAL | 9.8 | Apr 7, 2022 |
| CVE-2020-9492 | hadoop: WebHDFS client might send SPNEGO authorization header | HIGH | 8.8 | Jan 26, 2021 |
| CVE-2018-11764 | hadoop: privilege escalation in web endpoint | HIGH | 8.8 | Oct 21, 2020 |
| CVE-2018-11765 | hadoop: Potential information disclosure in Hadoop Web interfaces | HIGH | 7.5 | Sep 30, 2020 |
| CVE-2012-2945 | hadoop: symlink vulnerability in conf/hadoop-env.sh | HIGH | 7.5 | Oct 28, 2019 |
| CVE-2019-17195 | nimbus-jose-jwt: Uncaught exceptions while parsing a JWT | CRITICAL | 9.8 | Oct 15, 2019 |
| CVE-2018-11768 | hadoop: user/group information corruption through fsimage storing and reading | HIGH | 7.5 | Oct 4, 2019 |
| CVE-2018-8029 | hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user | HIGH | 8.8 | May 30, 2019 |
| CVE-2018-11767 | hadoop: Apache Hadoop KMS ACL regression | HIGH | 7.4 | Mar 18, 2019 |
| CVE-2018-1296 | hadoop: HDFS Permissive listXAttr Authorization | HIGH | 7.5 | Feb 7, 2019 |
| CVE-2018-11766 | hadoop: Privilege escalation to root (Incomplete fix for CVE-2016-6811) | HIGH | 8.8 | Nov 27, 2018 |
| CVE-2018-8009 | hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file | HIGH | 8.8 | Nov 13, 2018 |
| CVE-2017-15718 | The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications. | CRITICAL | 9.8 | Jan 24, 2018 |
| CVE-2017-15713 | Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files… | MEDIUM | 6.5 | Jan 19, 2018 |
| CVE-2017-3166 | In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable… | MEDIUM | 7.8 | Nov 13, 2017 |
| CVE-2012-4449 | Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled,… | CRITICAL | 9.8 | Oct 30, 2017 |
| CVE-2016-3086 | The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to… | CRITICAL | 9.8 | Sep 5, 2017 |
| CVE-2016-5001 | This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user o… | MEDIUM | 5.5 | Aug 30, 2017 |
Showing 1 to 25 of 37 CVEs