CVE-2022-25168
Apache Hadoop: command injection in FileUtil.unTar
Technology
Apache Hadoop
CVSS Score
9.8 / 10.0
Affected Versions
2.0.0 to 2.10.1; 3.0.0-alpha1 to 3.2.3; 3.3.0 to 3.3.2
Upstream Fix
2.10.2; 3.2.4; 3.3.3
Published
August 4, 2022
OSSeva Coverage
Fixed upstream
Description
FileUtil.unTar(File, File) does not escape the input file name before passing it to the shell, so an attacker can inject commands. In Hadoop 3.3 it is used only by InMemoryAliasMap.completeBootstrapTransfer, run by a local user, but in Hadoop 2.x it was used for YARN localization, where it allows remote code execution. Apache Spark's ADD ARCHIVE also reached it until SPARK-38305.
Is your Apache Hadoop deployment affected?
If you're running 2.0.0 to 2.10.1; 3.0.0-alpha1 to 3.2.3; 3.3.0 to 3.3.2, you need this patch. Book a discovery call to get covered.