Логотип exploitDog
bind:CVE-2021-25642
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-25642

Количество 4

Количество 4

redhat логотип

CVE-2021-25642

больше 3 лет назад

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-25642

больше 3 лет назад

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-25642

больше 3 лет назад

ZKConfigurationStore which is optionally used by CapacityScheduler of ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rr2m-gffv-mgrj

больше 3 лет назад

Deserialization of Untrusted Data in Apache Hadoop YARN

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-25642

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-25642

ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-25642

ZKConfigurationStore which is optionally used by CapacityScheduler of ...

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-rr2m-gffv-mgrj

Deserialization of Untrusted Data in Apache Hadoop YARN

CVSS3: 8.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу