[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2021-33036: Apache Hadoop Privilege escalation vulnerability
From:       Akira Ajisaka <aajisaka () apache ! org>
Date:       2022-06-15 14:10:21
Message-ID: 632698ac-e78b-79ac-3a37-7a6a3acf782c () apache ! org
[Download RAW message or body]

Severity: Critical

Description:

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, =
and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run =
arbitrary commands as root user.  Users should upgrade to Apache Hadoop 2.=
10.2, 3.2.3, 3.3.2 or higher.

Mitigation:

If you are using the affected version of Apache Hadoop and some users can =
escalate to yarn user and cannot escalate to root user, remove the =
permission to escalate to yarn user from them.

Credit:

Apache Hadoop would like to thank Hideyuki Furue for reporting and fixing =
this issue.

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic