CVE-2017-7669: Apache Hadoop privilege escalation

Varun Vasudev <[email protected]>
Newsgroups gmane.comp.apache.incubator.bigtop.user,gmane.comp.security.bugtraq,gmane.comp.security.oss.general,gmane.comp.apache.webservices.general
Message-ID <4A2FDA56-491B-4C2A-915F-C9D4A4BDB92A__19504.82031466$1496384421$gmane$org@apache.org>
CVE-2017-7669: Apache Hadoop privilege escalation

Severity: Critical

Vendor: The Apache Software Foundation

Versions affected: Hadoop 2.8.0, Hadoop 3.0.0-alpha1 and Hadoop 3.0.0-alpha2

Description:
The LinuxContainerExecutor runs docker commands as root with
insufficient input validation. When the docker feature is enabled,
authenticated users can run commands as root

Mitigation:
Users of Apache Hadoop 2.8.0 should leave Docker functionality disabled until Hadoop 2.8.1 is released.
Users of Apache Hadoop 3.0.0-alpha1 and Hadoop 3.0.0-alpha2 should upgrade to Hadoop 3.0.0-alpha3 or later.

Credit:
This issue was discovered by Allen Wittenauer.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.