<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: CVE-2021-33036 in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/CVE-2021-33036/m-p/349052#M235510</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/78359"&gt;@jeromedruais&lt;/a&gt;, Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2022 05:40:49 GMT</pubDate>
    <dc:creator>VidyaSargur</dc:creator>
    <dc:date>2022-07-29T05:40:49Z</dc:date>
    <item>
      <title>CVE-2021-33036</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CVE-2021-33036/m-p/348791#M235450</link>
      <description>&lt;DIV class="lia-quilt-row lia-quilt-row-main"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-main-content"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Hello, I would like to know if this CVE which impacts Apache Hadoop is already resolve into HDP or CDP products ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-33891" target="_blank" rel="noopener nofollow noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2021-33036&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:29:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CVE-2021-33036/m-p/348791#M235450</guid>
      <dc:creator>jeromedruais</dc:creator>
      <dc:date>2022-07-26T08:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-33036</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CVE-2021-33036/m-p/348798#M235454</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/78359"&gt;@jeromedruais&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This CVE will be addressed in CDP 7.1.8. Till then, you can use the below&amp;nbsp;precautions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. ensure in the linux sudoers files that there is no entry allowing users or groups to run as the yarn account. 2. ensure the cluster is kerberized&lt;/P&gt;&lt;P&gt;3. ensure the permissions for the yarn keytabs are not readable by others. find /var/run/cloudera-scm-agent/ | grep yarn | grep keytab (by default in kerberized cdp, others can't read these service keytabs)&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 09:57:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CVE-2021-33036/m-p/348798#M235454</guid>
      <dc:creator>rki_</dc:creator>
      <dc:date>2022-07-26T09:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2021-33036</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CVE-2021-33036/m-p/349052#M235510</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/78359"&gt;@jeromedruais&lt;/a&gt;, Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 05:40:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CVE-2021-33036/m-p/349052#M235510</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2022-07-29T05:40:49Z</dc:date>
    </item>
  </channel>
</rss>

