PT-2022-27526 · Apache · Apache Hama

Published

2022-11-21

·

Updated

2025-04-29

·

CVE-2022-45470

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Hama (affected versions not specified)
Description The issue is related to missing input validation in Apache Hama, which may cause information disclosure through path traversal and cross-site scripting (XSS). Since Apache Hama is end-of-life (EOL), these issues are not expected to be fixed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-45470
GHSA-4WFH-48V4-3R84

Affected Products

Apache Hama