Apache HadoopGHSA-h24p-qwf4-84q8
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
High7.5CVE-2017-7669 · Published May 17, 2022 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hadoop:hadoop-common Maven | < 2.8.1 | 2.8.1 |
| >= 3.0.0-alpha1, < 3.0.0-alpha3 | 3.0.0-alpha3 |
Details and references
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root. This issue is fixed in versions 2.8.1 and 3.0.0-alpha3.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2017-7669
More Apache Hadoop advisories
All Apache Hadoop| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Improper Authentication in Apache Hadoop CVE-2014-0229Medium6.5fixed in 0.23.11, 2.4.1 | Medium6.5 | 0.23.11, 2.4.1 |
| May 172022 | Improper Authentication in Apache Hadoop CVE-2013-2192Lowfixed in 0.23.9, 2.0.6-alpha | Low | 0.23.9, 2.0.6-alpha |
| May 172022 | Improper Access Control in Apache Hadoop CVE-2016-5393High8.8fixed in 2.6.5, 2.7.3 | High8.8 | 2.6.5, 2.7.3 |
| May 172022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop CVE-2015-1776Medium6.2fixed in 2.6.5 | Medium6.2 | 2.6.5 |
| May 142022 | Insecure Inherited Permissions in Apache Hadoop CVE-2016-6811High8.8fixed in 2.7.4 | High8.8 | 2.7.4 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop CVE-2016-5001Medium5.5fixed in 2.6.4, 2.7.2 | Medium5.5 | 2.6.4, 2.7.2 |