Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-33036

Опубликовано: 15 июн. 2022
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

A flaw was found in Hadoop Yarn. This flaw allows an attacker to benefit from permissions, escalate to a yarn user and run arbitrary commands as root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat Fuse 7hadoopNot affected
Red Hat Integration Camel K 1hadoopNot affected
Red Hat Integration Camel Quarkus 1hadoopNot affected
Red Hat Integration Data Virtualisation OperatorhadoopOut of support scope
Red Hat JBoss Data Grid 7hadoopOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2102826hadoop: privilege escalation via yarn user

EPSS

Процентиль: 84%
0.02095
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

CVSS3: 8.8
debian
больше 3 лет назад

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2. ...

CVSS3: 8.8
github
больше 3 лет назад

User account escalation in Apache Hadoop

EPSS

Процентиль: 84%
0.02095
Низкий

8.8 High

CVSS3