Executive Summary

Informations
Name CVE-2022-25168 First vendor Publication 2022-08-04
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 9.8
Base Score 9.8 Environmental Score 9.8
impact SubScore 5.9 Temporal Score 9.8
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It has been used in Hadoop 2.x for yarn localization, which does enable remote code execution. It is used in Apache Spark, from the SQL command ADD ARCHIVE. As the ADD ARCHIVE command adds new binaries to the classpath, being able to execute shell scripts does not confer new permissions to the caller. SPARK-38305. "Check existence of file before untarring/zipping", which is included in 3.3.0, 3.1.4, 3.2.2, prevents shell commands being executed, regardless of which version of the hadoop libraries are in use. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.3 or upper (including HADOOP-18136).

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25168

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 75

Sources (Detail)

https://lists.apache.org/thread/mxqnb39jfrwgs3j6phwvlrfq4mlox130
https://security.netapp.com/advisory/ntap-20220915-0007/
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Date Informations
2025-06-26 01:56:57
  • Multiple Updates
2025-06-25 12:18:49
  • Multiple Updates
2024-11-28 14:07:57
  • Multiple Updates
2024-08-02 13:34:27
  • Multiple Updates
2024-08-02 01:28:52
  • Multiple Updates
2024-02-02 02:33:15
  • Multiple Updates
2024-02-01 12:26:31
  • Multiple Updates
2023-09-05 13:27:37
  • Multiple Updates
2023-09-05 01:25:57
  • Multiple Updates
2023-09-02 13:25:56
  • Multiple Updates
2023-09-02 01:26:21
  • Multiple Updates
2023-08-12 13:32:18
  • Multiple Updates
2023-08-12 01:25:37
  • Multiple Updates
2023-08-11 13:24:10
  • Multiple Updates
2023-08-11 01:26:26
  • Multiple Updates
2023-08-06 13:21:59
  • Multiple Updates
2023-08-06 01:25:20
  • Multiple Updates
2023-08-04 13:22:26
  • Multiple Updates
2023-08-04 01:25:41
  • Multiple Updates
2023-07-14 13:22:27
  • Multiple Updates
2023-07-14 01:25:27
  • Multiple Updates
2023-06-26 17:27:28
  • Multiple Updates
2023-06-24 00:27:39
  • Multiple Updates
2023-03-29 02:24:13
  • Multiple Updates
2023-03-28 12:25:37
  • Multiple Updates
2022-10-29 00:27:38
  • Multiple Updates
2022-10-11 13:13:04
  • Multiple Updates
2022-10-11 01:24:49
  • Multiple Updates
2022-09-16 02:13:12
  • Multiple Updates
2022-08-10 21:27:09
  • Multiple Updates
2022-08-05 00:27:12
  • Multiple Updates
2022-08-04 21:27:15
  • First insertion