CVE-2017-7669
high
CVSS v3
7.5
CVSS v2
8.5
VIR risk
7.5
Description
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@apache.org — https://mail-archives.apache.org/mod_mbox/hadoop-user/201706.mbox/%3C4A2FDA56-491B-4C2A-915F-C9D4A4BDB92A%40apache.org%3E
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.hadoop:hadoop-common | <2.8.1 | 2.8.1 |
| Maven | org.apache.hadoop:hadoop-common | >=3.0.0-alpha1,<3.0.0-alpha3 | 3.0.0-alpha3 |
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.