CVE-2018-11766: Critical severity apache hadoop vulnerability
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Hadoop security issue?
The vulnerability ID for this Apache Hadoop security issue is CVE-2018-11766.
What is the severity of CVE-2018-11766?
The severity of CVE-2018-11766 is critical with a CVSS score of 8.8.
Which versions of Apache Hadoop are affected by CVE-2018-11766?
Apache Hadoop versions 2.7.4 to 2.7.6 are affected by CVE-2018-11766.
What is the potential impact of CVE-2018-11766?
An attacker who can escalate to the yarn user can potentially run arbitrary commands as the root user.
Are there any references for CVE-2018-11766?
Yes, you can find references for CVE-2018-11766 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/106035) and [Apache Hadoop mailing list](https://lists.apache.org/thread.html/ff37bbbe09d5f03090e2dd2c3dea95de16ef4249e731f19b8959ce4c@%3Cgeneral.hadoop.apache.org%3E).