Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-25642

Apache Hadoop YARN: ZKConfigurationStore deserializes data from ZooKeeper

Technology

Apache Hadoop

CVSS Score

8.8 / 10.0

Affected Versions

2.9.0 to 2.10.1; 3.0.0-alpha to 3.2.3; 3.3.0 to 3.3.3

Upstream Fix

2.10.2; 3.2.4; 3.3.4

Published

August 25, 2022

OSSeva Coverage

Fixed upstream

Description

ZKConfigurationStore, optionally used by the YARN CapacityScheduler, deserializes data read from ZooKeeper without validation. An attacker with access to ZooKeeper can run arbitrary commands as the YARN user.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 2.9.0 to 2.10.1; 3.0.0-alpha to 3.2.3; 3.3.0 to 3.3.3, you need this patch. Book a discovery call to get covered.