First published: Thu May 30 2019(Updated: )
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Hadoop | >=2.2.0<=2.8.4 | |
Apache Hadoop | >=3.0.1<=3.1.0 | |
Apache Hadoop | =2.9.0 | |
Apache Hadoop | =2.9.1 | |
Apache Hadoop | =3.0.0 | |
Apache Hadoop | =3.0.0-alpha1 | |
Apache Hadoop | =3.0.0-alpha2 | |
Apache Hadoop | =3.0.0-alpha3 | |
Apache Hadoop | =3.0.0-alpha4 | |
Apache Hadoop | =3.0.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8029 is a vulnerability in Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4 that allows a user who can escalate to yarn user to possibly run arbitrary commands as the root user.
The severity of CVE-2018-8029 is critical with a CVSS score of 8.8.
You can check if you are affected by CVE-2018-8029 by checking the version of Apache Hadoop installed on your system.
To fix CVE-2018-8029, you should upgrade your Apache Hadoop software to a version that is not affected by this vulnerability.
You can find more information about CVE-2018-8029 on the SecurityFocus website and the Apache Hadoop mailing list.