Path traversal in Hadoop - CVE-2018-8009

 

Path traversal in Hadoop - CVE-2018-8009

Published: November 20, 2018 / Updated: November 20, 2018


Vulnerability identifier: #VU15972
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8009
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct a directory traversal attack on the target system.

The vulnerability exists due to improper validation of files inside an archive file. A remote unauthenticated attacker can trick the victim into extracting a zip file that contains files that use directory traversal characters, cause a malicious file to be created outside the current working directory and cause a denial of service (DoS) condition or execute arbitrary code by overwriting other files on the system.

Successful exploitation of the vulnerability may result in system compromise.

Note: the vulnerability has been dubbed "Zip Slip".


Affected software

Hadoop
IBM PureData System for Operational Analytics
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Application Performance Management (APM)
Fuse
Fedora
hadoop
IBM InfoSphere Information Server

How to mitigate CVE-2018-8009

The vulnerability has been fixed in the versions 3.1.1, 3.0.3, 2.8.5, and 2.7.7.

Hadoop - addressed in versions 2.7.7, 2.8.5, 3.0.3, 3.1.1
Fuse - update to 7.5.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
hadoop - update to 2.7.6-4.fc28
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins