Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-33036

Apache Hadoop: yarn user can escalate to root

Technology

Apache Hadoop

CVSS Score

8.8 / 10.0

Affected Versions

2.2.0 to 2.10.1; 3.0.0-alpha1 to 3.1.4; 3.2.0 to 3.2.2; 3.3.0 to 3.3.1

Upstream Fix

2.10.2; 3.2.3; 3.3.2

Published

June 15, 2022

OSSeva Coverage

Fixed upstream

Description

A user who can escalate to the yarn user can possibly run arbitrary commands as root. The advisory's mitigation, where users can become yarn but not root, is to remove their permission to become yarn.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 2.2.0 to 2.10.1; 3.0.0-alpha1 to 3.1.4; 3.2.0 to 3.2.2; 3.3.0 to 3.3.1, you need this patch. Book a discovery call to get covered.