In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
{
"nvd_published_at": null,
"github_reviewed_at": "2019-05-31T16:08:38Z",
"cwe_ids": [
"CWE-285"
],
"severity": "HIGH",
"github_reviewed": true
}