Description
missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/21/1
https://lists.apache.org/thread/ztvoshd4kxvp5vlro52mpgpfxct4ft8l
Related Vulnerabilities
CVE-2022-25878 Vulnerability in npm package protobufjs
CVE-2014-6071 Vulnerability in maven package org.webjars.bower:jquery
CVE-2013-7285 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-45457 Vulnerability in maven package org.apache.kylin:kylin-server
CVE-2022-43435 Vulnerability in maven package org.jenkins-ci.plugins.plugin:fireline