CVE-2017-7669: Input Validation
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7669?
CVE-2017-7669 is classified as a high-severity vulnerability due to the potential for remote code execution as root.
How do I fix CVE-2017-7669?
To fix CVE-2017-7669, upgrade to Apache Hadoop versions 2.8.1, 3.0.0-alpha3, or later where the vulnerability is patched.
What is the impact of CVE-2017-7669?
The impact of CVE-2017-7669 allows authenticated users to execute arbitrary commands as the root user, leading to elevated privileges.
Which versions of Apache Hadoop are affected by CVE-2017-7669?
CVE-2017-7669 affects Apache Hadoop versions 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2.
Can CVE-2017-7669 be exploited remotely?
Yes, CVE-2017-7669 can be exploited remotely by authenticated users with access to the docker feature.