CVE-2018-8029

In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
apachehadoop
2.2.0 ≤
𝑥
≤ 2.8.4
apachehadoop
3.0.1 ≤
𝑥
≤ 3.1.0
apachehadoop
2.9.0
apachehadoop
2.9.1
apachehadoop
3.0.0
apachehadoop
3.0.0:alpha1
apachehadoop
3.0.0:alpha2
apachehadoop
3.0.0:alpha3
apachehadoop
3.0.0:alpha4
apachehadoop
3.0.0:beta1
𝑥
= Vulnerable software versions
References