Skip to content
Apache HadoopGHSA-h24p-qwf4-84q8

Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation

High7.5CVE-2017-7669 · Published May 17, 2022 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
< 2.8.12.8.1
>= 3.0.0-alpha1, < 3.0.0-alpha33.0.0-alpha3
Details and references

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root. This issue is fixed in versions 2.8.1 and 3.0.0-alpha3.

CVSS 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
CVE-2017-7669

More Apache Hadoop advisories

All Apache Hadoop
DateAdvisory
May 172022Improper Authentication in Apache Hadoop
CVE-2014-0229Medium6.5fixed in 0.23.11, 2.4.1
May 172022Improper Authentication in Apache Hadoop
CVE-2013-2192Lowfixed in 0.23.9, 2.0.6-alpha
May 172022Improper Access Control in Apache Hadoop
CVE-2016-5393High8.8fixed in 2.6.5, 2.7.3
May 172022Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2015-1776Medium6.2fixed in 2.6.5
May 142022Insecure Inherited Permissions in Apache Hadoop
CVE-2016-6811High8.8fixed in 2.7.4
May 132022Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-5001Medium5.5fixed in 2.6.4, 2.7.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.