Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25168

Опубликовано: 08 авг. 2022
Источник: redhat
CVSS3: 9.8

Описание

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It has been used in Hadoop 2.x for yarn localization, which does enable remote code execution. It is used in Apache Spark, from the SQL command ADD ARCHIVE. As the ADD ARCHIVE command adds new binaries to the classpath, being able to execute shell scripts does not confer new permissions to the caller. SPARK-38305. "Check existence of file before untarring/zipping", which is included in 3.3.0, 3.1.4, 3.2.2, prevents shell commands being executed, regardless of which version of the hadoop libraries are in use. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.3 or upper (including HADOOP-18136).

A flaw was found in the hadoop-common package. This flaw allows an attacker to benefit from command injection using the org.apache.hadoop.fs.FileUtil.unTarUsingTar function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2hadoopNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-mover-rclone-rhel8Not affected
Red Hat AMQ Broker 7hadoopNot affected
Red Hat Data Grid 8hadoopNot affected
Red Hat Fuse 7hadoopNot affected
Red Hat Integration Camel K 1hadoopFix deferred
Red Hat Integration Camel Quarkus 1hadoopFix deferred
Red Hat Integration Data Virtualisation OperatorhadoopOut of support scope
Red Hat JBoss Data Grid 7hadoopOut of support scope
Red Hat JBoss Data Virtualization 6hadoopOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2119084hadoop: Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTar

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It has been used in Hadoop 2.x for yarn localization, which does enable remote code execution. It is used in Apache Spark, from the SQL command ADD ARCHIVE. As the ADD ARCHIVE command adds new binaries to the classpath, being able to execute shell scripts does not confer new permissions to the caller. SPARK-38305. "Check existence of file before untarring/zipping", which is included in 3.3.0, 3.1.4, 3.2.2, prevents shell commands being executed, regardless of which version of the hadoop libraries are in use. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.3 or upper (including HADOOP-18136).

CVSS3: 9.8
debian
больше 3 лет назад

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the inp ...

CVSS3: 9.8
github
больше 3 лет назад

Apache Hadoop argument injection vulnerability

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость реализации интерфейса API FileUtil.unTar(File, File) платформы для распределенной разработки и выполнения программ Apache Hadoop, позволяющая нарушителю выполнить произвольные команды

9.8 Critical

CVSS3