CVE-2021-25642
published 2022-08-25CVE-2021-25642: ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.82%
76.2th percentile
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | >= 2.9.0 < 2.10.2 | 2.10.2 |
| apache | hadoop | >= 3.0.0 < 3.2.4 | 3.2.4 |
| apache | hadoop | >= 3.3.0 < 3.3.4 | 3.3.4 |
| apache_software_foundation | apache_hadoop | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_apache8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Hadoop: YARN remote code execution in ZKConfigurationStore of capacity scheduler
vendor_redhat·2022-08-25·CVSS 8.8
CVE-2021-25642 [HIGH] CWE-502 Hadoop: YARN remote code execution in ZKConfigurationStore of capacity scheduler
Hadoop: YARN remote code execution in ZKConfigurationStore of capacity scheduler
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
Statement: No Red Hat products are affected by this vulnerability. While some do use Hadoop YARN, none provide the affected Capacity Scheduler component.
Package: hadoop-yarn (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: hadoop-yarn (Red Hat build of Apache Camel for Spring Boot 3) - Not affected
Package: hadoop-yarn
Apache
Apache hadoop: CVE-2021-25642
vendor_apache·CVSS 8.8
CVE-2021-25642 [HIGH] Apache hadoop: CVE-2021-25642
Apache hadoop: CVE-2021-25642
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this.
GHSA
Deserialization of Untrusted Data in Apache Hadoop YARN
ghsa·2022-08-26
CVE-2021-25642 [HIGH] CWE-502 Deserialization of Untrusted Data in Apache Hadoop YARN
Deserialization of Untrusted Data in Apache Hadoop YARN
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
OSV
Deserialization of Untrusted Data in Apache Hadoop YARN
osv·2022-08-26
CVE-2021-25642 [HIGH] Deserialization of Untrusted Data in Apache Hadoop YARN
Deserialization of Untrusted Data in Apache Hadoop YARN
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-25
Published