Description
missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/21/1
https://lists.apache.org/thread/ztvoshd4kxvp5vlro52mpgpfxct4ft8l
Related Vulnerabilities
CVE-2020-2183 Vulnerability in maven package org.jenkins-ci.plugins:copyartifact
CVE-2022-37260 Vulnerability in npm package steal
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-unix-common-tests
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger
CVE-2019-10349 Vulnerability in maven package org.jenkins-ci.plugins:depgraph-view