Loading HuntDB...

GHSA-58jx-f5rf-qgqf

GitHub Security Advisory

User account escalation in Apache Hadoop

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

Affected Packages

Maven org.apache.hadoop:hadoop-yarn-server-common
Affected versions: 2.2.0 (fixed in 2.10.2)
Maven org.apache.hadoop:hadoop-yarn-server-common
Affected versions: 3.0.0 (fixed in 3.2.3)
Maven org.apache.hadoop:hadoop-yarn-server-common
Affected versions: 3.3.0 (fixed in 3.3.2)

Related CVEs

Key Information

GHSA ID
GHSA-58jx-f5rf-qgqf
Published
June 16, 2022 12:00 AM
Last Modified
June 24, 2022 7:54 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.hadoop:hadoop-yarn-server-common
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.