Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2022-25168

Apache Hadoop: command injection in FileUtil.unTar

Technology

Apache Hadoop

CVSS Score

9.8 / 10.0

Affected Versions

2.0.0 to 2.10.1; 3.0.0-alpha1 to 3.2.3; 3.3.0 to 3.3.2

Upstream Fix

2.10.2; 3.2.4; 3.3.3

Published

August 4, 2022

OSSeva Coverage

Fixed upstream

Description

FileUtil.unTar(File, File) does not escape the input file name before passing it to the shell, so an attacker can inject commands. In Hadoop 3.3 it is used only by InMemoryAliasMap.completeBootstrapTransfer, run by a local user, but in Hadoop 2.x it was used for YARN localization, where it allows remote code execution. Apache Spark's ADD ARCHIVE also reached it until SPARK-38305.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 2.0.0 to 2.10.1; 3.0.0-alpha1 to 3.2.3; 3.3.0 to 3.3.2, you need this patch. Book a discovery call to get covered.