CVE-2021-25642
Summary
| CVE | CVE-2021-25642 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-25 14:15:00 UTC |
| Updated | 2023-02-10 17:37:00 UTC |
| Description | ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-25642 Apache Hadoop Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| lists.apache.org/thread/g6vf2h4wdgzzdgk91mqozhs58wotq150 | MISC | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Apache Hadoop would like to thank Liu Ximing for reporting this issue.
There are currently no legacy QID mappings associated with this CVE.