CVE-2018-8029: Critical severity apache hadoop vulnerability
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-8029?
CVE-2018-8029 is a vulnerability in Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4 that allows a user who can escalate to yarn user to possibly run arbitrary commands as the root user.
What is the severity of CVE-2018-8029?
The severity of CVE-2018-8029 is critical with a CVSS score of 8.8.
How can I check if I am affected by CVE-2018-8029?
You can check if you are affected by CVE-2018-8029 by checking the version of Apache Hadoop installed on your system.
How do I fix CVE-2018-8029?
To fix CVE-2018-8029, you should upgrade your Apache Hadoop software to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2018-8029?
You can find more information about CVE-2018-8029 on the SecurityFocus website and the Apache Hadoop mailing list.