Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-45470


missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.


Published

2022-11-21T16:15:25.970

Last Modified

2025-04-29T14:15:27.557

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-20
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache hama ≤ 1.7.1 Yes

References