CVE-2021-33036

HIGH

Apache Hadoop <2.10.2, <3.2.3, <3.3.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

Scores

CVSS v3 8.8
EPSS 0.0209
EPSS Percentile 84.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22 CWE-264 CWE-24
Status published
Products (3)
apache/hadoop 3.0.0 alpha1 (4 CPE variants)
apache/hadoop 2.2.0 - 2.10.2
org.apache.hadoop/hadoop-yarn-server-common 2.2.0 - 2.10.2Maven
Published Jun 15, 2022
Tracked Since Feb 18, 2026