Back to search
CVE-2018-8009
Published: Nov 13, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Hadoop | affected Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 |
References
https://snyk.io/research/zip-slip-vulnerability
x_refsource_MISC
105927
vdb-entry
x_refsource_BID
[hadoop-user] 20181122 CVE-2018-8009: Apache Hadoop distributed cache archive vulnerability
mailing-list
x_refsource_MLIST
RHSA-2019:3892
vendor-advisory
x_refsource_REDHAT
[druid-commits] 20201008 [druid] branch master updated: Suppress CVE-2018-11765 for hadoop dependencies (#10485)
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now