#VU16165 Command injection in Hadoop - CVE-2018-11766
Published: November 28, 2018 / Updated: November 29, 2018
Hadoop
Apache Foundation
Description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper security restrictions. A remote attacker can escalate to yarn user access and execute arbitrary commands with root privileges on a targeted system.