CVE-2018-8029
published 2019-05-30CVE-2018-8029: In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands…
PriorityP359high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
3.98%
89.3th percentile
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | 2.2.0 – 2.8.4 | — |
| apache | hadoop | 3.0.1 – 3.1.0 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_apache8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user
vendor_redhat·2019-05-30·CVSS 8.8
CVE-2018-8029 [HIGH] CWE-284 hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user
hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
A flaw was found in Apache Hadoop in versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4. A user who can escalate to a yarn user can possibly run arbitrary commands as root user. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: hadoop-core (Red Hat Fuse 7) - Not affected
Package: hadoop-core (Red Hat JBoss Data Grid 7) - Not affected
Package: hadoop-core (Red Hat JBoss Data Virtualization 6) - Not affected
Package: hadoop-core (Red H
Apache
Apache hadoop: CVE-2018-8029
vendor_apache·CVSS 8.8
CVE-2018-8029 [HIGH] Apache hadoop: CVE-2018-8029
Apache hadoop: CVE-2018-8029
A user who can escalate to yarn user can possibly run arbitrary commands as root user.
GHSA
Privilege escalation vulnerability in Apache Hadoop
ghsa·2019-05-31
CVE-2018-8029 [HIGH] CWE-285 Privilege escalation vulnerability in Apache Hadoop
Privilege escalation vulnerability in Apache Hadoop
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
OSV
Privilege escalation vulnerability in Apache Hadoop
osv·2019-05-31
CVE-2018-8029 [HIGH] Privilege escalation vulnerability in Apache Hadoop
Privilege escalation vulnerability in Apache Hadoop
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8029 hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user
bugzilla·2020-01-27·CVSS 8.8
CVE-2018-8029 [HIGH] CVE-2018-8029 hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user
CVE-2018-8029 hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Reference:
https://lists.apache.org/thread.html/3d6831c3893cd27b6850aea2feff7d536888286d588e703c6ffd2e82@%3Cuser.hadoop.apache.org%3E
Discussion:
Created hadoop tracking bugs for this issue:
Affects: fedora-all [bug 1795323]
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Data Virtualization & Services 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
The container openshift4/ose-metering-hadoop is packa
Bugzilla
CVE-2018-8029 hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user [fedora-all]
bugzilla·2020-01-27·CVSS 8.8
CVE-2018-8029 [HIGH] CVE-2018-8029 hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user [fedora-all]
CVE-2018-8029 hadoop: a user who can escalate to yarn user can possibly run arbitrary commands as root user [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
http://www.securityfocus.com/bid/108518https://lists.apache.org/thread.html/0b8d58e02dbd0fb8bf7320c514fe58da1d6728bdc150f1ba04e0d9fc%40%3Cissues.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/17084c09e6dedf60efe08028b429c92ffd28aacc28454e4fa924578a%40%3Cgeneral.hadoop.apache.org%3Ehttps://lists.apache.org/thread.html/a0164b87660223a2d491f83c88f905fe1a9fa8dc795148d9b0d968c8%40%3Cdev.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/a97c53a81e639ca2fc7b8f61a4fcd1842c2a78544041244a7c624727%40%3Cissues.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/r4dddf1705dbedfa94392913b2dad1cd2d1d89040facd389eea0b3510%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rb21df54a4e39732ce653d2aa5672e36a792b59eb6717f2a06bb8d02a%40%3Ccommits.druid.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190617-0001/http://www.securityfocus.com/bid/108518https://lists.apache.org/thread.html/0b8d58e02dbd0fb8bf7320c514fe58da1d6728bdc150f1ba04e0d9fc%40%3Cissues.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/17084c09e6dedf60efe08028b429c92ffd28aacc28454e4fa924578a%40%3Cgeneral.hadoop.apache.org%3Ehttps://lists.apache.org/thread.html/a0164b87660223a2d491f83c88f905fe1a9fa8dc795148d9b0d968c8%40%3Cdev.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/a97c53a81e639ca2fc7b8f61a4fcd1842c2a78544041244a7c624727%40%3Cissues.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/r4dddf1705dbedfa94392913b2dad1cd2d1d89040facd389eea0b3510%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rb21df54a4e39732ce653d2aa5672e36a792b59eb6717f2a06bb8d02a%40%3Ccommits.druid.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190617-0001/
2019-05-30
Published