Note:
This project will be discontinued after December 13, 2021. [more]
2017-04-11
In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Products | Hadoop |
Type | Permissions, Privileges, and Access Controls (CWE-264) |
First patch | - None (likely due to unavailable code) |
Links | https://lists.apache.org/thread.html/9ba3c12bbdfd5b2cae60909e48f92608e00c8d99196390b8cfeca307%40%3Cgeneral.hadoop.apache.org%3E |