Improper Validation of Integrity Check Value Affecting hadoop-fips-3.5 package, versions <3.5.0-r3


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.58% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-HADOOPFIPS35-18969175
  • published20 Aug 2026
  • disclosed12 Aug 2024

Introduced: 12 Aug 2024

CVE-2024-41909  (opens in a new tab)
CWE-354  (opens in a new tab)

How to fix?

Upgrade Chainguard hadoop-fips-3.5 to version 3.5.0-r3 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream hadoop-fips-3.5 package and not the hadoop-fips-3.5 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack

The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.

CVSS Base Scores

version 3.1