{
  "@id": "urn:uuid:59f37af5-d713-4f17-a96f-9e43fea9f63f",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6811 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2016-6811"
      },
      "action_statement": "Vulnerability CVE-2016-6811 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-15713 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2017-15713"
      },
      "action_statement": "Vulnerability CVE-2017-15713 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-15718 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2017-15718"
      },
      "action_statement": "Vulnerability CVE-2017-15718 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-3166 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2017-3166"
      },
      "action_statement": "Vulnerability CVE-2017-3166 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-7669 does not affect version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry. Target Apache Hadoop 2.7.3 is not affected by CVE-2017-7669. The vulnerability exists in the sanitize_docker_command() function within docker support for the native LinuxContainerExecutor, which was introduced in version 2.8.0 (after this target version). Version 2.7.3's native container-executor only supports four commands (INITIALIZE_CONTAINER, LAUNCH_CONTAINER, SIGNAL_CONTAINER, DELETE_AS_USER) and has no docker command handling. The vulnerable code pattern, including the sanitize_docker_command function and docker command processing logic, does not exist in this version. The CVE description confirms it affects \"2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2\" - all versions released after 2.7.3.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2017-7669"
      },
      "impact_statement": "Target Apache Hadoop 2.7.3 is not affected by CVE-2017-7669. The vulnerability exists in the sanitize_docker_command() function within docker support for the native LinuxContainerExecutor, which was introduced in version 2.8.0 (after this target version). Version 2.7.3's native container-executor only supports four commands (INITIALIZE_CONTAINER, LAUNCH_CONTAINER, SIGNAL_CONTAINER, DELETE_AS_USER) and has no docker command handling. The vulnerable code pattern, including the sanitize_docker_command function and docker command processing logic, does not exist in this version. The CVE description confirms it affects \"2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2\" - all versions released after 2.7.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-11765 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2018-11765"
      },
      "action_statement": "Vulnerability CVE-2018-11765 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-11766 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2018-11766"
      },
      "action_statement": "Vulnerability CVE-2018-11766 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-11768 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2018-11768"
      },
      "action_statement": "Vulnerability CVE-2018-11768 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-1296 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2018-1296"
      },
      "action_statement": "Vulnerability CVE-2018-1296 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-8009 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2018-8009"
      },
      "action_statement": "Vulnerability CVE-2018-8009 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-8029 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2018-8029"
      },
      "action_statement": "Vulnerability CVE-2018-8029 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-9492 does not affect version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry. Version 2.7.3 is not affected by CVE-2020-9492: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ca65409836d2949e9a9408d40bec0177b414cd5d\". No backport needed.",
      "vulnerability": {
        "name": "CVE-2020-9492"
      },
      "impact_statement": "Version 2.7.3 is not affected by CVE-2020-9492: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ca65409836d2949e9a9408d40bec0177b414cd5d\". No backport needed."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-25642 does not affect version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry. Apache Hadoop 2.7.3 is not affected by CVE-2021-25642. The vulnerable component ZKConfigurationStore does not exist in this version. According to JIRA YARN-6840, ZKConfigurationStore was introduced in version 2.9.0 (resolved September 2017), which postdates the target version 2.7.3. Exhaustive searches confirmed no ZKConfigurationStore class, no related imports, no ZooKeeper-based configuration deserialization in the capacity scheduler, and no ObjectInputStream usage in the resourcemanager code.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2021-25642"
      },
      "impact_statement": "Apache Hadoop 2.7.3 is not affected by CVE-2021-25642. The vulnerable component ZKConfigurationStore does not exist in this version. According to JIRA YARN-6840, ZKConfigurationStore was introduced in version 2.9.0 (resolved September 2017), which postdates the target version 2.7.3. Exhaustive searches confirmed no ZKConfigurationStore class, no related imports, no ZooKeeper-based configuration deserialization in the capacity scheduler, and no ObjectInputStream usage in the resourcemanager code."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33036 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2021-33036"
      },
      "action_statement": "Vulnerability CVE-2021-33036 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-37404 does not affect version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry. Version determined not vulnerable by backport analysis (terminalized from patch_application_manual/not_vulnerable)",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2021-37404"
      },
      "impact_statement": "Version determined not vulnerable by backport analysis (terminalized from patch_application_manual/not_vulnerable)"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25168 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2022-25168"
      },
      "action_statement": "Vulnerability CVE-2022-25168 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-26612 does not affect version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry. Version 2.7.3 is not vulnerable. Summary: CVE-2022-26612 does not affect Hadoop version 2.7.3. The vulnerability requires symlink handling functionality in the unpackEntries method that was not introduced until HADOOP-15170 (February 2, 2018), which postdates version 2.7.3. The target codebase lacks the vulnerable feature entirely. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-26612"
      },
      "impact_statement": "Version 2.7.3 is not vulnerable. Summary: CVE-2022-26612 does not affect Hadoop version 2.7.3. The vulnerability requires symlink handling functionality in the unpackEntries method that was not introduced until HADOOP-15170 (February 2, 2018), which postdates version 2.7.3. The target codebase lacks the vulnerable feature entirely. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-registry@2.7.3.tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23454 is fixed in version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-yarn-registry.",
      "vulnerability": {
        "name": "CVE-2024-23454"
      }
    }
  ]
}
