Path traversal in Hadoop - CVE-2018-8009
Published: November 20, 2018 / Updated: November 20, 2018
Vulnerability details
The vulnerability allows a remote attacker to conduct a directory traversal attack on the target system.
The vulnerability exists due to improper validation of files inside an archive file. A remote unauthenticated attacker can trick the victim into extracting a zip file that contains files that use directory traversal characters, cause a malicious file to be created outside the current working directory and cause a denial of service (DoS) condition or execute arbitrary code by overwriting other files on the system.
Successful exploitation of the vulnerability may result in system compromise.
Note: the vulnerability has been dubbed "Zip Slip".
Affected software
IBM PureData System for Operational Analytics
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Application Performance Management (APM)
Fuse
Fedora
hadoop
IBM InfoSphere Information Server
How to mitigate CVE-2018-8009
Fuse - update to 7.5.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
hadoop - update to 2.7.6-4.fc28
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Path traversal in Apache Hadoop
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Path traversal in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM Application Performance Management
- Fedora 28 update for hadoop