CVE-2017-7669

high
Published 2017-06-05 · Modified 2023-11-08
CVSS v3
7.5
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
8.5
VIR risk
7.5

Description

Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://mail-archives.apache.org/mod_mbox/hadoop-user/201706.mbox/%3C4A2FDA56-491B-4C2A-915F-C9D4A4BDB92A%40apache.org%3E

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.hadoop:hadoop-common<2.8.12.8.1
java Mavenorg.apache.hadoop:hadoop-common>=3.0.0-alpha1,<3.0.0-alpha33.0.0-alpha3

Application impact

VendorProductVersionsFixed
apache apachehadoop2.8.0
apache apachehadoop3.0.0

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.