Vulnerabilities > Apache > Hadoop > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-08-04 CVE-2022-25168 Unspecified vulnerability in Apache Hadoop
Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell.
network
low complexity
apache
critical
9.8
2022-06-13 CVE-2021-37404 Unspecified vulnerability in Apache Hadoop
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code.
network
low complexity
apache
critical
9.8
2022-04-07 CVE-2022-26612 Link Following vulnerability in Apache Hadoop
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes.
network
low complexity
apache CWE-59
critical
9.8
2019-10-15 CVE-2019-17195 Improper Handling of Exceptional Conditions vulnerability in multiple products
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
network
low complexity
connect2id apache oracle CWE-755
critical
9.8
2018-01-24 CVE-2017-15718 Unspecified vulnerability in Apache Hadoop 2.7.3/2.7.4
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
network
low complexity
apache
critical
9.8
2017-10-30 CVE-2012-4449 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Apache Hadoop
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.
network
low complexity
apache CWE-327
critical
9.8
2017-09-05 CVE-2016-3086 Information Exposure vulnerability in Apache Hadoop
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
network
low complexity
apache CWE-200
critical
9.8