In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Loading...
Loading...
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
May 30, 2019
November 21, 2024
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.hadoop:hadoop-main | 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.1.0 | 3.1.1 | — |
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2018-8029
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.