In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apache hadoop 2.8.0 |
||
apache hadoop 3.0.0 |