CVE-2021-33036
published 2022-06-15CVE-2021-33036: In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary…
high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | >= 2.2.0 < 2.10.2 | 2.10.2 |
| apache | hadoop | >= 3.0.1 < 3.2.3 | 3.2.3 |
| apache | hadoop | >= 3.3.0 < 3.3.2 | 3.3.2 |
| apache_software_foundation | apache_hadoop | — | — |