Apache Hadoop ȨÏÞÌáÉý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-05-31

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-8029£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º8.8


ÊÜÓ°ÏìµÄ°æ±¾


Apache Hadoop 3.0.0-alpha1 µ½ 3.1.0°æ±¾
Apache Hadoop 2.9.0 µ½ 2.9.1°æ±¾

Apache Hadoop 2.2.0 µ½ 2.8.4°æ±¾


·ì϶¸ÅÊö


Apache HadoopÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»Ì׿ªÔ´µÄÉ¢²¼Ê½ÏµÍ³»ù´¡¼Ü¹¹£¬Ëü¿ÉÄܶԴóÁ¿Êý¾Ý½øÐÐÉ¢²¼Ê½´¦Ö㬲¢ÓµÓи߿¿µÃסÐÔ¡¢¸ßÀ©´óÐÔ¡¢¸ßÈÝ´íÐÔµÈÌØµã  ¡£


Apache Hadoop¶à¸ö°æ±¾´æÔÚ±¾µØÌáȨ·ì϶£¨CVE-2018-8029£©£¬ÀûÓø÷ì϶£¬¹¥»÷Õ߿ɽ«ËÁÒâÄÜÌáÉýµ½ yarn ȨÏÞµÄÓû§ÌáÉýµ½ root ȨÏÞ£¬ÒÔÖ´ÐжñÒâ´úÂë  ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP  ¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼ÒÔÏÂа汾½¨¸´·ì϶£¬ÏÂÔØµØÖ·£º

https://hadoop.apache.org/releases.html  ¡£
Apache Hadoop 2.8.5»ò¸ü¸ß°æ±¾
Apache Hadoop 2.9.2»ò¸ü¸ß°æ±¾

Apache Hadoop 3.1.1»ò¸ü¸ß°æ±¾


²Î¿¼Á´½Ó


https://hadoop.apache.org/cve_list.html