12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.apache.hadoop:hadoop-common is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.3
CVE-2024-23454
Apache Hadoop: Temporary File Local Information Disclosure
CRITICAL 9.8
CVE-2022-26612
Path traversal in Hadoop
UNKNOWN
CVE-2013-2192
Improper Authentication in Apache Hadoop
HIGH 8.8
CVE-2020-9492
Improper Privilege Management in Apache Hadoop
CRITICAL 9.8
CVE-2021-37404
Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
CRITICAL 9.8
CVE-2022-25168
Apache Hadoop argument injection vulnerability
HIGH 7.5
CVE-2017-7669
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
HIGH 8.8
CVE-2016-6811
Insecure Inherited Permissions in Apache Hadoop
HIGH 8.8
CVE-2016-5393
Improper Access Control in Apache Hadoop
MEDIUM 5.5
CVE-2016-5001
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
MEDIUM 6.2
CVE-2015-1776
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
MEDIUM 6.5
CVE-2014-0229
Improper Authentication in Apache Hadoop
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes