ASA-2018-00102 – Apache Hadoop: Privilege escalation vulnerability


Allele Security Alert

ASA-2018-00102

Identifier(s)

ASA-2018-00102, CVE-2018-8029

Title

Privilege escalation vulnerability

Vendor(s)

Unknown

Product(s)

Apache Hadoop

Affected version(s)

Apache Hadoop versions 3.0.0-alpha1 to 3.1.0
Apache Hadoop versions 2.9.0 to 2.9.1
Apache Hadoop versions 2.2.0 to 2.8.4

Fixed version(s)

Apache Hadoop version 2.8.5
Apache Hadoop version 2.9.2
Apache Hadoop version 3.1.1

Proof of concept

Unknown

Description

A user who can escalate to yarn user can possibly run arbitrary commands as root user.

Technical details

Unknown

Credits

Miklos Szegedi

Reference(s)

CVE-2018-8029: Apache Hadoop Privilege escalation vulnerability
https://lists.apache.org/thread.html/17084c09e6dedf60efe08028b429c92ffd28aacc28454e4fa924578a@%3Cgeneral.hadoop.apache.org%3E

CVE-2018-8029: Apache Hadoop Privilege escalation vulnerability
https://seclists.org/oss-sec/2019/q2/132

Hadoop CVE List
https://hadoop.apache.org/cve_list.html

CVE-2018-8029
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8029

CVE-2018-8029
https://nvd.nist.gov/vuln/detail/CVE-2018-8029

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: October 2, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.