Loading HuntDB...

GHSA-rmpj-7c96-mrg8

GitHub Security Advisory

Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

Affected Packages

Maven org.apache.hadoop:hadoop-common
Affected versions: 3.3.0 (fixed in 3.3.2)
Maven org.apache.hadoop:hadoop-common
Affected versions: 3.0.0 (fixed in 3.2.3)
Maven org.apache.hadoop:hadoop-common
Affected versions: 0 (fixed in 2.10.2)

Related CVEs

Key Information

GHSA ID
GHSA-rmpj-7c96-mrg8
Published
June 14, 2022 12:00 AM
Last Modified
June 27, 2023 8:51 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
org.apache.hadoop:hadoop-common
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.