CVE-2016-5393: Apache Hadoop Privilege escalation vulnerability
Yongjun Zhang <[email protected]>
| Newsgroups | gmane.comp.security.bugtraq,gmane.comp.security.oss.general,gmane.comp.apache.webservices.general |
|---|---|
| Message-ID | <CAA0W1bTbUmUUSF1rjRpX-2DvWutcrPt7TJSWUcSLg1F0gyHG1Q__7178.20569775558$1480380118$gmane$org@mail.gmail.com> |
Hi, Please see below the official announcement of a critical security vulnerability that's discovered and subsequently fixed in Apache Hadoop releases. Thanks and best regards, --Yongjun ---------- CVE-2016-5393: Apache Hadoop Privilege escalation vulnerability Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Hadoop 2.6.x, 2.7.x Description: A remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands as the hdfs user. Mitigation: 2.7.x users should upgrade to 2.7.3 2.6.x users should upgrade to 2.6.5 Impact: A remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as HDFS service. Credit: This issue was discovered by Freddie Rice. ----------