Vulnerabilities
Vulnerable Software
Apache:  >> Hadoop  >> 2.8.0  Security Vulnerabilities
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
CVSS Score
6.5
EPSS Score
0.001
Published
2018-01-19
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.
CVSS Score
7.5
EPSS Score
0.003
Published
2017-06-05


Contact Us

Shodan ® - All rights reserved