CVE-2021-25642
HIGHApache Hadoop 2.9.0-2.10.1 - Remote Code Execution via ZKConfigurationStore Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-25642. PoCs published by safe3s.
AI-analyzed exploit summary The repository contains only a minimal README with the CVE identifier and no exploit code, technical details, or functional content.
Description
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to ZooKeeper can run arbitrary commands as YARN user by exploiting this. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.4 or later (containing YARN-11126) if ZKConfigurationStore is used.
Exploits (1)
The repository contains only a minimal README with the CVE identifier and no exploit code, technical details, or functional content.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H