Description
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.
Affected products
- Apache Software Foundation / Apache Hadoop2.8.0 – 2.8.0
- Apache Software Foundation / Apache Hadoop3.0.0-alpha1 and 3.0.0-alpha2 – 3.0.0-alpha1 and 3.0.0-alpha2