Loading HuntDB...

GHSA-h24p-qwf4-84q8

GitHub Security Advisory

Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root. This issue is fixed in versions 2.8.1 and 3.0.0-alpha3.

Affected Packages

Maven org.apache.hadoop:hadoop-common
Affected versions: 0 (fixed in 2.8.1)
Maven org.apache.hadoop:hadoop-common
Affected versions: 3.0.0-alpha1 (fixed in 3.0.0-alpha3)

Related CVEs

Key Information

GHSA ID
GHSA-h24p-qwf4-84q8
Published
May 17, 2022 2:41 AM
Last Modified
November 22, 2022 6:47 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.hadoop:hadoop-common
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.