Vulnerability Description
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Hadoop | >= 0.23.0, <= 0.23.11 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105927Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3892
- https://hadoop.apache.org/cve_list.html#cve-2018-8009-http-cve-mitre-org-cgi-binVendor Advisory
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c24
- https://lists.apache.org/thread.html/a1c227745ce30acbcf388c5b0cc8423e8bf495d619c
- https://lists.apache.org/thread.html/r4dddf1705dbedfa94392913b2dad1cd2d1d89040fa
- https://lists.apache.org/thread.html/rb21df54a4e39732ce653d2aa5672e36a792b59eb67
- https://snyk.io/research/zip-slip-vulnerabilityExploitThird Party Advisory
- http://www.securityfocus.com/bid/105927Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3892
- https://hadoop.apache.org/cve_list.html#cve-2018-8009-http-cve-mitre-org-cgi-binVendor Advisory
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c24
- https://lists.apache.org/thread.html/a1c227745ce30acbcf388c5b0cc8423e8bf495d619c
- https://lists.apache.org/thread.html/r4dddf1705dbedfa94392913b2dad1cd2d1d89040fa
- https://lists.apache.org/thread.html/rb21df54a4e39732ce653d2aa5672e36a792b59eb67
FAQ
What is CVE-2018-8009?
CVE-2018-8009 is a vulnerability with a CVSS score of 8.8 (HIGH). Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
How severe is CVE-2018-8009?
CVE-2018-8009 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-8009?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Hadoop.