CVE-2018-8029: Apache Hadoop
High severity, CVSS 8.8. EPSS: 3.9% chance of exploitation in the next 30 days.
In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Affected products
- Apache Hadoop: from 2.2.0, up to and including 2.8.4; from 3.0.1, up to and including 3.1.0; version 2.9.0 only; version 2.9.1 only; version 3.0.0 only
Published 2019-05-30. Last modified 2026-06-17.