QID 995956
Date Published: 2023-11-20
QID 995956: Java (Maven) Security Update for org.apache.hadoop:hadoop-yarn-project (GHSA-94jh-j374-9r3j)
Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root privileges.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-94jh-j374-9r3j for updates and patch information.
Vendor References
- GHSA-94jh-j374-9r3j -
github.com/advisories/GHSA-94jh-j374-9r3j
CVEs related to QID 995956
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-94jh-j374-9r3j | org.apache.hadoop:hadoop-yarn-project |
|