Known vulnerabilities in Hadoop

Software: Hadoop
Software CPE: cpe:2.3:a:apache_foundation:hadoop:*:*:*:*:*:*:*:*
Total vulnerabilities: 31
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Hadoop Hadoop is affected by 31 known vulnerabilities: 10 high, 12 medium, 9 low Critical High Medium Low

Vulnerabilities (31)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122008 - Out-of-bounds write
CVE-2025-27821
CWE-787 Low
No
No
3.4.2 24.01.2026 SB2026012411
SB2026042214
SB2026042288
#VU110016 - Deserialization of Untrusted Data
CVE-2021-25642
CWE-502 Medium
No
No
2.10.2, 3.2.4, 3.3.4 02.06.2025 SB2022082559
SB2025060221
SB2026082843
#VU97712 - Incorrect Default Permissions
CVE-2024-23454
CWE-276 Low
No
No
3.4.0 26.09.2024 SB2024092604
SB20241108105
SB20241108106
and 14 more
#VU69531 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-25168
CWE-78 High
No
No
2.10.2, 3.2.4, 3.3.3 23.11.2022 SB2022112314
SB2022112334
SB2022121525
and 10 more
#VU68739 - Heap-based Buffer Overflow
CVE-2021-37404
CWE-122 High
No
No
2.10.2, 3.2.3, 3.3.2 26.10.2022 SB2022062017
SB2022102620
SB2023092025
and 3 more
#VU64513 - Permissions, Privileges, and Access Controls
CVE-2021-33036
CWE-264 Medium
No
No
2.10.2, 3.2.3, 3.3.2 20.06.2022 SB2022062017
SB2022102620
SB2022102155
and 3 more
#VU62082 - Security Features
CVE-2022-26612
CWE-254 Medium
No
No
3.2.3 12.04.2022 SB2022041216
SB2022103132
SB2022112334
and 8 more
#VU50000 - Permissions, Privileges, and Access Controls
CVE-2020-9492
CWE-264 Medium
No
No
2.10.1, 3.1.4, 3.2.2 26.01.2021 SB2021012612
SB2021120219
SB2021120336
and 12 more
#VU25728 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
0.4.1 alpha 02.03.2020 SB2019091625
#VU35142 - Improper Link Resolution Before File Access ('Link Following')
CVE-2012-2945
CWE-59 Medium
No
No
- 29.10.2019 SB2019102930
#VU18689 - Permissions, Privileges, and Access Controls
CVE-2018-8029
CWE-264 High
No
No
2.8.5, 2.9.2, 3.1.1 06.06.2019 SB2019060604
SB2021120219
SB2021120336
and 4 more
#VU18114 - Improper Access Control
CVE-2018-11767
CWE-284 Medium
No
No
2.7.7, 2.8.5, 2.9.2 02.04.2019 SB2019040202
#VU17254 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1296
CWE-200 Low
No
No
2.7.6, 2.8.4, 2.9.1, 3.0.1 29.01.2019 SB2019012907
#VU16165 - Command injection
CVE-2018-11766
CWE-77 Low
No
No
2.7.7 28.11.2018 SB2018112904
SB2024091911
SB2018113020
and 1 more
#VU16008 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 High
No
No
- 22.11.2018 SB2018112204
#VU15972 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-8009
CWE-22 High
No
No
2.7.7, 2.8.5, 3.0.3, 3.1.1 20.11.2018 SB2018112008
SB2019112016
SB2022072128
and 4 more
#VU12602 - Command injection
CVE-2016-6811
CWE-77 Low
No
No
- 14.05.2018 SB2018051407
SB2018070222
SB2018070660
and 2 more
#VU37593 - Improper input validation
CVE-2017-15718
CWE-20 High
No
No
- 24.01.2018 SB2018012425
SB2024051037
SB2018070222
and 1 more
#VU37998 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2012-4449
CWE-327 High
No
No
- 30.10.2017 SB2017103019
#VU38374 - Exposure of sensitive information to an unauthorized actor
CVE-2016-5001
CWE-200 Low
No
No
- 30.08.2017 SB2017083014


Showing elements 1 - 20 out of 31