First published: Tue Jun 19 2018(Updated: )
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Hadoop | >=0.23.0<=0.23.11 | |
Apache Hadoop | >=2.0.0<=2.7.6 | |
Apache Hadoop | >=2.8.0<=2.8.4 | |
Apache Hadoop | >=2.9.0<=2.9.1 | |
Apache Hadoop | >=3.0.0<=3.0.2 | |
Apache Hadoop | =2.0.0-alpha | |
Apache Hadoop | =3.0.0-alpha1 | |
Apache Hadoop | =3.0.0-alpha2 | |
Apache Hadoop | =3.0.0-alpha3 | |
Apache Hadoop | =3.0.0-alpha4 | |
Apache Hadoop | =3.0.0-beta1 | |
Apache Hadoop | =3.1.0 | |
redhat/hadoop | <3.1.1 | 3.1.1 |
redhat/hadoop | <3.0.3 | 3.0.3 |
redhat/hadoop | <2.9.2 | 2.9.2 |
redhat/hadoop | <2.8.5 | 2.8.5 |
redhat/hadoop | <2.7.7 | 2.7.7 |
maven/org.apache.hadoop:hadoop-main | <2.7.7 | 2.7.7 |
maven/org.apache.hadoop:hadoop-main | >=2.8.0<2.8.5 | 2.8.5 |
maven/org.apache.hadoop:hadoop-main | >=2.9.0<2.9.2 | 2.9.2 |
maven/org.apache.hadoop:hadoop-main | >=3.0.0<3.0.3 | 3.0.3 |
maven/org.apache.hadoop:hadoop-main | =3.1.0 | 3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8009 is a vulnerability in Apache Hadoop versions 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, and 0.23.0 to 0.23.11.
CVE-2018-8009 has a severity rating of 8.8, which is classified as high.
The zip slip vulnerability is a security issue where an attacker can exploit the extraction of ZIP files to overwrite arbitrary files on the file system.
You can fix CVE-2018-8009 by updating to Apache Hadoop version 3.1.1, 3.0.3, 2.9.2, 2.8.5, 2.7.7, or by applying the appropriate patches provided by Red Hat.
You can find more information about CVE-2018-8009 on the Snyk research page, the GitHub commit, and the Red Hat Bugzilla page.