CVE-2018-8009

HIGH

Apache Hadoop Path Traversal via Zip Slip

Title source: llm
STIX 2.1

Description

Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.

Scores

CVSS v3 8.8
EPSS 0.0485
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (5)
apache/hadoop 2.0.0 alpha
apache/hadoop 3.0.0 alpha1 (5 CPE variants)
apache/hadoop 3.1.0
apache/hadoop 0.23.0 - 0.23.11
org.apache.hadoop/hadoop-main 3.1.0 - 3.1.1Maven
Published Nov 13, 2018
Tracked Since Feb 18, 2026