
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Hadoop versions prior to 3.2.3 and 3.3.1 through 3.3.2 contain a vulnerability in the unTar function (CVE-2022-26612). The vulnerability was discovered in early 2022 and publicly disclosed in April 2022. The issue affects the FileUtil component, specifically the unpackEntries functionality on Windows systems (GitHub Advisory).
The vulnerability exists in the unTar function which uses unTarUsingJava function on Windows and the built-in tar utility on Unix systems. While the function verifies that extracted TAR entries are under the expected targetDirPath, it fails to apply the same restriction to extracted symlinks. On Windows systems, the getCanonicalPath doesn't resolve symbolic links, which allows bypassing the directory traversal check (GitHub Advisory).
The vulnerability has been assessed with a CVSS v3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Successful exploitation could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS) (NetApp Advisory).
The vulnerability was fixed in Apache Hadoop versions 3.2.3 and 3.3.2. The fix was implemented in the main branch on March 10, 2022, and version 3.2.3 with the fix was released on March 28, 2022 (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."