cbcvebase.
CVE-2021-33036
published 2022-06-15

CVE-2021-33036: In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.58%
88.2th percentile
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachehadoop
apachehadoop
apachehadoop>= 2.2.0 < 2.10.22.10.2
apachehadoop>= 3.0.1 < 3.2.33.2.3
apachehadoop>= 3.3.0 < 3.3.23.3.2
apache_software_foundationapache_hadoop

Detection & IOCsextracted from sources · hover to see the quote

  • Privilege escalation path: attacker escalates to 'yarn' user, then leverages yarn user permissions to execute arbitrary commands as root. Monitor for unexpected privilege escalation to the 'yarn' OS user account.
  • Focus detection on Apache Hadoop YARN component specifically. Audit who has permission to escalate to the 'yarn' user and alert on any such escalation events in affected versions (2.2.0–2.10.1, 3.0.0-alpha1–3.1.4, 3.2.0–3.2.2, 3.3.0–3.3.1).
  • ·Exploitation requires the attacker to first have the ability to escalate to the 'yarn' OS user. Environments where no unprivileged user can become 'yarn' are not exploitable. Audit sudoers and PAM configurations for yarn user access.
  • ·Red Hat packages for openshift-logging/elasticsearch6-rhel8, hadoop in Red Hat Fuse 7, Red Hat Integration Camel K 1, and Red Hat Integration Camel Quarkus 1 are confirmed NOT affected. hadoop in Red Hat Integration Data Virtualisation Operator and Red Hat JBoss Data Grid 7 are out of support scope.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_apache8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.