CVE Published: 27/11/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Hadoop Status : PUBLISHED
CVE-2018-11766 Description
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.