PT-2022-10651 · Apache · Apache Hadoop

Igor Chervatyuk

·

Published

2022-06-13

·

Updated

2023-06-27

·

CVE-2021-37404

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Hadoop versions prior to 2.10.2 Apache Hadoop versions prior to 3.2.3 Apache Hadoop versions prior to 3.3.2
Description There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. This issue occurs when a file path provided by a user is opened without validation, which may result in a denial of service or arbitrary code execution.
Recommendations For versions prior to 2.10.2, upgrade to Apache Hadoop 2.10.2 or higher. For versions prior to 3.2.3, upgrade to Apache Hadoop 3.2.3 or higher. For versions prior to 3.3.2, upgrade to Apache Hadoop 3.3.2 or higher.

Fix

DoS

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-37404
GHSA-RMPJ-7C96-MRG8
OESA-2022-2092

Affected Products

Apache Hadoop