Количество 4
Количество 4
CVE-2021-25642
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
CVE-2021-25642
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
CVE-2021-25642
ZKConfigurationStore which is optionally used by CapacityScheduler of ...
GHSA-rr2m-gffv-mgrj
Deserialization of Untrusted Data in Apache Hadoop YARN
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-25642 ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
CVE-2021-25642 ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used. | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
CVE-2021-25642 ZKConfigurationStore which is optionally used by CapacityScheduler of ... | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-rr2m-gffv-mgrj Deserialization of Untrusted Data in Apache Hadoop YARN | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад |
Уязвимостей на страницу