Hadoop YARN REST API 未授权访问导致远程代码执行漏洞
Open
- Dominant language
- Java
- Stars
- 17.4k
- Forks
- 5.7k
- PR merge metrics
- No merged PRs in 30d
Description
hadoop-yarn-server-common-2.6.0.jar#/META-INF/maven/org.apache.hadoop/hadoop-yarn-server-common/pom.xml
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by inspecting hadoop-yarn-server-common-2.6.0.jar and its META-INF/maven/org.apache.hadoop/hadoop-yarn-server-common/pom.xml entry to determine how this dependency is included in DataX. Verify the reported YARN REST API exposure and identify the affected dependency or configuration. Done means the vulnerability is confirmed and an appropriate remediation is defined.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- hadoop, java
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100