CVE-2021-37404

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/06/2022
Last modified:
27/06/2023

Description

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 2.9.0 (including) 2.10.2 (excluding)
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 3.0.0 (including) 3.1.4 (including)
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 3.2.0 (including) 3.2.3 (excluding)
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 3.3.0 (including) 3.3.2 (excluding)