CVE-2017-7669: Apache Hadoop

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.

Affected products

  • Apache Hadoop: version 2.8.0 only; version 3.0.0 only

Published 2017-06-05. Last modified 2026-06-17.