CVE-2018-8009: Apache Hadoop
High severity, CVSS 8.8. EPSS: 6.7% chance of exploitation in the next 30 days.
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
Affected products
- Apache Hadoop: from 0.23.0, up to and including 0.23.11; from 2.0.0, up to and including 2.7.6; from 2.8.0, up to and including 2.8.4; from 2.9.0, up to and including 2.9.1; from 3.0.0, up to and including 3.0.2; version 2.0.0 only; …
Published 2018-11-13. Last modified 2026-06-17.