CVE-2018-8009
hadoop: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
Apache Hadoop 3.1.0, 3.0.0-alpha a 3.0.2, 2.9.0 a 2.9.1, 2.8.0 a 2.8.4, 2.0.0-alpha a 2.7.6 y 0.23.0 a 0.23.11 puede explotarse mediante la vulnerabilidad "zip slip" en lugares que aceptan un archivo zip.
This release of Red Hat Fuse 7.5.0 serves as a replacement for Red Hat Fuse 7.4, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include code execution, denial of service, deserialization, information leakage, and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-09 CVE Reserved
- 2018-11-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-04-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (10)
URL | Date | SRC |
---|---|---|
https://snyk.io/research/zip-slip-vulnerability | 2024-08-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | >= 0.23.0 <= 0.23.11 Search vendor "Apache" for product "Hadoop" and version " >= 0.23.0 <= 0.23.11" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | >= 2.0.0 <= 2.7.6 Search vendor "Apache" for product "Hadoop" and version " >= 2.0.0 <= 2.7.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | >= 2.8.0 <= 2.8.4 Search vendor "Apache" for product "Hadoop" and version " >= 2.8.0 <= 2.8.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | >= 2.9.0 <= 2.9.1 Search vendor "Apache" for product "Hadoop" and version " >= 2.9.0 <= 2.9.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | >= 3.0.0 <= 3.0.2 Search vendor "Apache" for product "Hadoop" and version " >= 3.0.0 <= 3.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.0 Search vendor "Apache" for product "Hadoop" and version "2.0.0" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 3.0.0 Search vendor "Apache" for product "Hadoop" and version "3.0.0" | alpha1 |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 3.0.0 Search vendor "Apache" for product "Hadoop" and version "3.0.0" | alpha2 |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 3.0.0 Search vendor "Apache" for product "Hadoop" and version "3.0.0" | alpha3 |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 3.0.0 Search vendor "Apache" for product "Hadoop" and version "3.0.0" | alpha4 |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 3.0.0 Search vendor "Apache" for product "Hadoop" and version "3.0.0" | beta1 |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 3.1.0 Search vendor "Apache" for product "Hadoop" and version "3.1.0" | - |
Affected
|