Privilege escalation vulnerability in Apache Hadoop
High severity
GitHub Reviewed
Published
May 31, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
>= 2.2.0, < 2.8.4
>= 2.9.0, < 2.9.2
>= 3.0.0, < 3.1.1
Patched versions
2.8.4
2.9.2
3.1.1
Description
Reviewed
May 31, 2019
Published to the GitHub Advisory Database
May 31, 2019
Last updated
Jan 9, 2023
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
References