CVE-2021-33036
published 2022-06-15CVE-2021-33036: In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.58%
88.2th percentile
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | >= 2.2.0 < 2.10.2 | 2.10.2 |
| apache | hadoop | >= 3.0.1 < 3.2.3 | 3.2.3 |
| apache | hadoop | >= 3.3.0 < 3.3.2 | 3.3.2 |
| apache_software_foundation | apache_hadoop | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Privilege escalation path: attacker escalates to 'yarn' user, then leverages yarn user permissions to execute arbitrary commands as root. Monitor for unexpected privilege escalation to the 'yarn' OS user account. ↗
- →Focus detection on Apache Hadoop YARN component specifically. Audit who has permission to escalate to the 'yarn' user and alert on any such escalation events in affected versions (2.2.0–2.10.1, 3.0.0-alpha1–3.1.4, 3.2.0–3.2.2, 3.3.0–3.3.1). ↗
- ·Exploitation requires the attacker to first have the ability to escalate to the 'yarn' OS user. Environments where no unprivileged user can become 'yarn' are not exploitable. Audit sudoers and PAM configurations for yarn user access. ↗
- ·Red Hat packages for openshift-logging/elasticsearch6-rhel8, hadoop in Red Hat Fuse 7, Red Hat Integration Camel K 1, and Red Hat Integration Camel Quarkus 1 are confirmed NOT affected. hadoop in Red Hat Integration Data Virtualisation Operator and Red Hat JBoss Data Grid 7 are out of support scope. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_apache8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hadoop: privilege escalation via yarn user
vendor_redhat·2022-06-15·CVSS 8.8
CVE-2021-33036 [HIGH] CWE-502 hadoop: privilege escalation via yarn user
hadoop: privilege escalation via yarn user
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
A flaw was found in Hadoop Yarn. This flaw allows an attacker to benefit from permissions, escalate to a yarn user and run arbitrary commands as root.
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: hadoop (Red Hat Fuse 7) - Not affected
Package: hadoop (Red Hat Integration Camel K 1) - Not affected
Package: hadoop (Red Hat Integration Camel Quarkus 1) - Not affected
Package: hadoop (Red Hat Integration Data Virtualisation Operato
Apache
Apache hadoop: CVE-2021-33036
vendor_apache·CVSS 8.8
CVE-2021-33036 [HIGH] Apache hadoop: CVE-2021-33036
Apache hadoop: CVE-2021-33036
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, A user who can escalate to yarn user can possibly run arbitrary commands as root user. If you are using the affected version of Apache Hadoop and some users can escalate to yarn user and cannot escalate to root user, remove the permission to escalate to yarn user from them.
OSV
User account escalation in Apache Hadoop
osv·2022-06-16
CVE-2021-33036 [HIGH] User account escalation in Apache Hadoop
User account escalation in Apache Hadoop
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
GHSA
User account escalation in Apache Hadoop
ghsa·2022-06-16
CVE-2021-33036 [HIGH] CWE-22 User account escalation in Apache Hadoop
User account escalation in Apache Hadoop
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/06/15/2https://lists.apache.org/thread/ctr84rmo3xd2tzqcx2b277c8z692vhl5https://security.netapp.com/advisory/ntap-20220722-0003/http://www.openwall.com/lists/oss-security/2022/06/15/2https://lists.apache.org/thread/ctr84rmo3xd2tzqcx2b277c8z692vhl5https://security.netapp.com/advisory/ntap-20220722-0003/
2022-06-15
Published