Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2022-26612

Apache Hadoop: unTar follows symlinks and writes outside the target directory on Windows

Technology

Apache Hadoop

CVSS Score

9.8 / 10.0

Affected Versions

before 3.2.3; 3.3.x before 3.3.3

Upstream Fix

3.2.3; 3.3.3

Published

April 7, 2022

OSSeva Coverage

Fixed upstream

Description

On Windows, unTar uses unTarUsingJava, where getCanonicalPath does not resolve symbolic links. A TAR entry can create a symlink pointing outside the extraction directory and a later entry can write an arbitrary file through it. Unix systems are protected by the same path check. The advisory's mitigations are not to run YARN daemons as a user that can create symlinks on Windows, and not to use symlinks in TAR files.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running before 3.2.3; 3.3.x before 3.3.3, you need this patch. Book a discovery call to get covered.