Allele Security Alert
ASA-2018-00102
Identifier(s)
ASA-2018-00102, CVE-2018-8029
Title
Privilege escalation vulnerability
Vendor(s)
Unknown
Product(s)
Apache Hadoop
Affected version(s)
Apache Hadoop versions 3.0.0-alpha1 to 3.1.0
Apache Hadoop versions 2.9.0 to 2.9.1
Apache Hadoop versions 2.2.0 to 2.8.4
Fixed version(s)
Apache Hadoop version 2.8.5
Apache Hadoop version 2.9.2
Apache Hadoop version 3.1.1
Proof of concept
Unknown
Description
A user who can escalate to yarn user can possibly run arbitrary commands as root user.
Technical details
Unknown
Credits
Miklos Szegedi
Reference(s)
CVE-2018-8029: Apache Hadoop Privilege escalation vulnerability
https://lists.apache.org/thread.html/17084c09e6dedf60efe08028b429c92ffd28aacc28454e4fa924578a@%3Cgeneral.hadoop.apache.org%3E
CVE-2018-8029: Apache Hadoop Privilege escalation vulnerability
https://seclists.org/oss-sec/2019/q2/132
Hadoop CVE List
https://hadoop.apache.org/cve_list.html
CVE-2018-8029
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8029
CVE-2018-8029
https://nvd.nist.gov/vuln/detail/CVE-2018-8029
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: October 2, 2019