CVE-2017-7669

Description

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.298

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-7669 are fixed in Apache - hadoop-common 2.8.1Windows
Vulnerabilities CVE-2017-7669 are fixed in Apache - hadoop-common 3.0.0Windows
Vulnerabilities CVE-2017-7669 are fixed in Apache - hadoop-common for Linux 2.8.1Linux
Vulnerabilities CVE-2017-7669 are fixed in Apache - hadoop-common for Linux 3.0.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234