CVE-2017-7669: Apache Hadoop privilege escalation
Varun Vasudev <[email protected]>
| Newsgroups | gmane.comp.apache.incubator.bigtop.user,gmane.comp.security.bugtraq,gmane.comp.security.oss.general,gmane.comp.apache.webservices.general |
|---|---|
| Message-ID | <4A2FDA56-491B-4C2A-915F-C9D4A4BDB92A__19504.82031466$1496384421$gmane$org@apache.org> |
CVE-2017-7669: Apache Hadoop privilege escalation Severity: Critical Vendor: The Apache Software Foundation Versions affected: Hadoop 2.8.0, Hadoop 3.0.0-alpha1 and Hadoop 3.0.0-alpha2 Description: The LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root Mitigation: Users of Apache Hadoop 2.8.0 should leave Docker functionality disabled until Hadoop 2.8.1 is released. Users of Apache Hadoop 3.0.0-alpha1 and Hadoop 3.0.0-alpha2 should upgrade to Hadoop 3.0.0-alpha3 or later. Credit: This issue was discovered by Allen Wittenauer.