CVE-2018-8009
13.11.2018, 21:29
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
Vendor | Product | Version |
---|---|---|
apache | hadoop | 0.23.0 ≤ 𝑥 ≤ 0.23.11 |
apache | hadoop | 2.0.0 ≤ 𝑥 ≤ 2.7.6 |
apache | hadoop | 2.8.0 ≤ 𝑥 ≤ 2.8.4 |
apache | hadoop | 2.9.0 ≤ 𝑥 ≤ 2.9.1 |
apache | hadoop | 3.0.0 ≤ 𝑥 ≤ 3.0.2 |
apache | hadoop | 2.0.0:alpha |
apache | hadoop | 3.0.0:alpha1 |
apache | hadoop | 3.0.0:alpha2 |
apache | hadoop | 3.0.0:alpha3 |
apache | hadoop | 3.0.0:alpha4 |
apache | hadoop | 3.0.0:beta1 |
apache | hadoop | 3.1.0 |
𝑥
= Vulnerable software versions
References