Back to search
CVE-2017-7669
Published: Jun 2, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Hadoop | affected 2.8.0affected 3.0.0-alpha1 and 3.0.0-alpha2 |
References
98795
vdb-entry
x_refsource_BID
[hadoop-user] 20170602 CVE-2017-7669: Apache Hadoop privilege escalation
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now