alibaba / alibaba/DataX

Hadoop YARN REST API 未授权访问导致远程代码执行漏洞

Open
#2,170 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
17.4k
Forks
5.7k
PR merge metrics
No merged PRs in 30d

Description

hadoop-yarn-server-common-2.6.0.jar#/META-INF/maven/org.apache.hadoop/hadoop-yarn-server-common/pom.xml

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by inspecting hadoop-yarn-server-common-2.6.0.jar and its META-INF/maven/org.apache.hadoop/hadoop-yarn-server-common/pom.xml entry to determine how this dependency is included in DataX. Verify the reported YARN REST API exposure and identify the affected dependency or configuration. Done means the vulnerability is confirmed and an appropriate remediation is defined.

Written by the indexing model from the issue text.

Assessment

Tech stack
hadoop, java
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.