// For flags

CVE-2021-37404

Heap buffer overflow in libhdfs native library

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

Se presenta un potencial desbordamiento del búfer de la pila en el código nativo de Apache Hadoop libhdfs. La apertura de una ruta de archivo proporcionada por el usuario sin que sea comprobada puede resultar en una denegación de servicio o una ejecución de código arbitrario. Los usuarios deben actualizar a Apache Hadoop versiones 2.10.2, 3.2.3, 3.3.2 o superiores

*Credits: This issue was discovered by Igor Chervatyuk.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-23 CVE Reserved
  • 2022-06-13 CVE Published
  • 2024-06-09 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Hadoop
Search vendor "Apache" for product "Hadoop"
>= 2.9.0 < 2.10.2
Search vendor "Apache" for product "Hadoop" and version " >= 2.9.0 < 2.10.2"
-
Affected
Apache
Search vendor "Apache"
Hadoop
Search vendor "Apache" for product "Hadoop"
>= 3.0.0 <= 3.1.4
Search vendor "Apache" for product "Hadoop" and version " >= 3.0.0 <= 3.1.4"
-
Affected
Apache
Search vendor "Apache"
Hadoop
Search vendor "Apache" for product "Hadoop"
>= 3.2.0 < 3.2.3
Search vendor "Apache" for product "Hadoop" and version " >= 3.2.0 < 3.2.3"
-
Affected
Apache
Search vendor "Apache"
Hadoop
Search vendor "Apache" for product "Hadoop"
>= 3.3.0 < 3.3.2
Search vendor "Apache" for product "Hadoop" and version " >= 3.3.0 < 3.3.2"
-
Affected