Apache · Apache Hadoop · CVE-2021-37404
**Name of the Vulnerable Software and Affected Versions**
Apache Hadoop versions prior to 2.10.2
Apache Hadoop versions prior to 3.2.3
Apache Hadoop versions prior to 3.3.2
**Description**
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. This issue occurs when a file path provided by a user is opened without validation, which may result in a denial of service or arbitrary code execution.
**Recommendations**
For versions prior to 2.10.2, upgrade to Apache Hadoop 2.10.2 or higher.
For versions prior to 3.2.3, upgrade to Apache Hadoop 3.2.3 or higher.
For versions prior to 3.3.2, upgrade to Apache Hadoop 3.3.2 or higher.