Apache Hadoop ȨÏÞÌáÉýÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-05-31Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-8029£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬CVSS·ÖÖµ£º8.8
ÊÜÓ°ÏìµÄ°æ±¾
Apache Hadoop 2.9.0 µ½ 2.9.1°æ±¾
Apache Hadoop 2.2.0 µ½ 2.8.4°æ±¾
Îó²î¸ÅÊö
Apache HadoopÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»Ì׿ªÔ´µÄÂþÑÜʽϵͳ»ù´¡¼Ü¹¹£¬ËüÄܹ»¶Ô´ó×ÚÊý¾Ý¾ÙÐÐÂþÑÜʽ´¦Öóͷ££¬²¢¾ßÓи߿ɿ¿ÐÔ¡¢¸ßÀ©Õ¹ÐÔ¡¢¸ßÈÝ´íÐÔµÈÌØµã¡£
Apache Hadoop¶à¸ö°æ±¾±£´æÍâµØÌáȨÎó²î£¨CVE-2018-8029£©£¬Ê¹ÓøÃÎó²î£¬¹¥»÷Õ߿ɽ«í§ÒâÄÜÌáÉýµ½ yarn ȨÏÞµÄÓû§ÌáÉýµ½ root ȨÏÞ£¬ÒÔÖ´ÐжñÒâ´úÂë¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
ÐÞ¸´½¨Òé
https://hadoop.apache.org/releases.html¡£
Apache Hadoop 2.8.5»ò¸ü¸ß°æ±¾
Apache Hadoop 2.9.2»ò¸ü¸ß°æ±¾
Apache Hadoop 3.1.1»ò¸ü¸ß°æ±¾
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ