XML External Entity Injection (XXE) Affecting org.apache.hadoop:hadoop-hdfs package, versions [,3.3.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about XML External Entity Injection (XXE) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHEHADOOP-2329722
  • published7 Mar 2022
  • disclosed5 Jan 2022
  • creditAshutosh Gupta

Introduced: 5 Jan 2022

CVE NOT AVAILABLE CWE-611  (opens in a new tab)

How to fix?

Upgrade org.apache.hadoop:hadoop-hdfs to version 3.3.2 or higher.

Overview

org.apache.hadoop:hadoop-hdfs is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models.

Affected versions of this package are vulnerable to XML External Entity Injection (XXE) due to insecure parsing of XML files via the OfflineEditsXmlLoader.java tool.

CVSS Scores

version 3.1