QID 980826
QID 980826: Java (maven) Security Update for org.apache.hadoop:hadoop-main (GHSA-37pw-qw47-4jxm)
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-37pw-qw47-4jxm for updates pertaining to this vulnerability.
Vendor References
- GHSA-37pw-qw47-4jxm -
github.com/advisories/GHSA-37pw-qw47-4jxm
CVEs related to QID 980826
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-37pw-qw47-4jxm | org.apache.hadoop:hadoop-main |
|