org.apache.hadoop:hadoop-yarn-server-nodemanager@2.7.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.hadoop:hadoop-yarn-server-nodemanager package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Command Execution

org.apache.hadoop:hadoop-yarn-server-nodemanager is a resource management and job scheduling technology in the open source Hadoop distributed processing framework.

Affected versions of this package are vulnerable to Arbitrary Command Execution. A user who could escalate to yarn user could possibly run arbitrary commands as root user.

How to fix Arbitrary Command Execution?

Upgrade org.apache.hadoop:hadoop-yarn-server-nodemanager to version 2.7.4 or higher.

Note On the 27/11/2018 it was found that the fix for version 2.7.4 is incomplete and the version 2.7.7 was published with the complete fix.

[2.2.0,2.7.4)