Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58jx-f5rf-qgqf

Опубликовано: 16 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

User account escalation in Apache Hadoop

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

Пакеты

Наименование

org.apache.hadoop:hadoop-yarn-server-common

maven
Затронутые версииВерсия исправления

>= 2.2.0, < 2.10.2

2.10.2

Наименование

org.apache.hadoop:hadoop-yarn-server-common

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.2.3

3.2.3

Наименование

org.apache.hadoop:hadoop-yarn-server-common

maven
Затронутые версииВерсия исправления

>= 3.3.0, < 3.3.2

3.3.2

EPSS

Процентиль: 84%
0.02095
Низкий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-502

Связанные уязвимости

CVSS3: 8.8
redhat
больше 3 лет назад

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

CVSS3: 8.8
nvd
больше 3 лет назад

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

CVSS3: 8.8
debian
больше 3 лет назад

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2. ...

EPSS

Процентиль: 84%
0.02095
Низкий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-502