Command injection in Hadoop - CVE-2018-11766
Published: November 28, 2018 / Updated: November 29, 2018
Vulnerability details
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper security restrictions. A remote attacker can escalate to yarn user access and execute arbitrary commands with root privileges on a targeted system.
Affected software
Fedora
watsonx.data
hadoop
How to mitigate CVE-2018-11766
watsonx.data - update to 2.0.2
hadoop - addressed in versions 2.7.7-1.fc28, 2.7.7-1.fc29