#VU16008 OS command injection in Hadoop
Published: November 22, 2018 / Updated: June 26, 2023
Hadoop
Apache Foundation
Description
The vulnerability exists in Hadoop YARN mechanism due to insufficient validation of user-supplied input. A remote unauthenticated attacker can inject and execute arbitrary shell commands to infect Hadoop clusters on Linux servers with unsophisticated new bots (DemonBot, Mirai bot) and compromise vulnerable system.