Lucene search

K
cvelistApacheCVELIST:CVE-2018-8009
HistoryNov 13, 2018 - 9:00 p.m.

CVE-2018-8009

2018-11-1321:00:00
apache
www.cve.org
2

8.5 High

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.8%

Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.

CNA Affected

[
  {
    "product": "Apache Hadoop",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11"
      }
    ]
  }
]

8.5 High

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.8%