|
Message-ID: <CAP+3qq5GcGNU-gdn0BW7fxaXr8_F2v6MuUgRx+Ho1pN=p1U6qA@mail.gmail.com> Date: Thu, 22 Nov 2018 10:25:00 +0900 From: Akira Ajisaka <aajisaka@...che.org> To: general@...oop.apache.org, user@...oop.apache.org, security@...oop.apache.org, oss-security@...ts.openwall.com, security@...k.io Subject: CVE-2018-8009: Apache Hadoop distributed cache archive vulnerability CVE-2018-8009: Apache Hadoop distributed cache archive vulnerability Severity: Severe Vendor: The Apache Software Foundation Versions Affected: Hadoop 0.23.0 to 0.23.11 Hadoop 2.0.0-alpha to 2.7.6 Hadoop 2.8.0 to 2.8.4 Hadoop 2.9.0 to 2.9.1 Hadoop 3.0.0-alpha to 3.0.2 Hadoop 3.1.0 Users affected: User running the YARN NodeManager daemon and YARN users that leverage public archives in the distributed cache Impact: Vulnerability allows a cluster user to publish a public archive that can affect other files owned by the user running the YARN NodeManager daemon. If the impacted files belong to another already localized, public archive on the node then code can be injected into the jobs of other cluster users using the public archive. Mitigation: Users should upgrade to Apache Hadoop 2.7.7, 2.8.5, 2.9.2, 3.0.3, or 3.1.1. Credit: This issue was discovered by Snyk Security Research Team https://snyk.io/research/zip-slip-vulnerability
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.