Back to Vulnerability Directory
HIGHFixed upstream

CVE-2018-8029

Apache Hadoop: yarn user can escalate to root in older lines

Technology

Apache Hadoop

CVSS Score

8.8 / 10.0

Affected Versions

2.2.0 to 2.8.4; 2.9.0 to 2.9.1; 3.0.0-alpha1 to 3.1.0

Upstream Fix

2.8.5; 2.9.2; 3.1.1

Published

May 30, 2019

OSSeva Coverage

Fixed upstream

Description

A user who can escalate to the yarn user can possibly run arbitrary commands as root. NVD's score is CVSS 3.0. Hadoop 2.7 and 3.0 have no fixed release.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 2.2.0 to 2.8.4; 2.9.0 to 2.9.1; 3.0.0-alpha1 to 3.1.0, you need this patch. Book a discovery call to get covered.