[prev in list] [next in list] [prev in thread] [next in thread]
List: oss-security
Subject: [oss-security] CVE-2018-8009: Apache Hadoop distributed cache archive vulnerability
From: Akira Ajisaka <aajisaka () apache ! org>
Date: 2018-11-22 1:25:00
Message-ID: CAP+3qq5GcGNU-gdn0BW7fxaXr8_F2v6MuUgRx+Ho1pN=p1U6qA () mail ! gmail ! com
[Download RAW message or body]
CVE-2018-8009: Apache Hadoop distributed cache archive vulnerability
Severity: Severe
Vendor: The Apache Software Foundation
Versions Affected:
Hadoop 0.23.0 to 0.23.11
Hadoop 2.0.0-alpha to 2.7.6
Hadoop 2.8.0 to 2.8.4
Hadoop 2.9.0 to 2.9.1
Hadoop 3.0.0-alpha to 3.0.2
Hadoop 3.1.0
Users affected: User running the YARN NodeManager daemon and YARN
users that leverage public archives in the distributed cache
Impact: Vulnerability allows a cluster user to publish a public
archive that can affect other files owned by the user running the YARN
NodeManager daemon. If the impacted files belong to another already
localized, public archive on the node then code can be injected into
the jobs of other cluster users using the public archive.
Mitigation: Users should upgrade to Apache Hadoop 2.7.7, 2.8.5, 2.9.2,
3.0.3, or 3.1.1.
Credit: This issue was discovered by Snyk Security Research Team
https://snyk.io/research/zip-slip-vulnerability
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic