CVE-2022-26612
Apache Hadoop: unTar follows symlinks and writes outside the target directory on Windows
Technology
Apache Hadoop
CVSS Score
9.8 / 10.0
Affected Versions
before 3.2.3; 3.3.x before 3.3.3
Upstream Fix
3.2.3; 3.3.3
Published
April 7, 2022
OSSeva Coverage
Fixed upstream
Description
On Windows, unTar uses unTarUsingJava, where getCanonicalPath does not resolve symbolic links. A TAR entry can create a symlink pointing outside the extraction directory and a later entry can write an arbitrary file through it. Unix systems are protected by the same path check. The advisory's mitigations are not to run YARN daemons as a user that can create symlinks on Windows, and not to use symlinks in TAR files.
Is your Apache Hadoop deployment affected?
If you're running before 3.2.3; 3.3.x before 3.3.3, you need this patch. Book a discovery call to get covered.