Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-25642


ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.


Published

2022-08-25T14:15:09.067

Last Modified

2024-11-21T05:55:11.800

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-502
  • Type: Secondary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache hadoop < 2.10.2 Yes
Application apache hadoop < 3.2.4 Yes
Application apache hadoop < 3.3.4 Yes

References