漏洞描述 YARN是hadoop系统上的资源统⼀管理平台,其主要作用是实现集群资源的统⼀管理和调度,可以把MapReduce计算框架作为⼀个应用程序运行在YARN系统之上。YARN提供了默认开放在8088和8090的REST API(默认前者)允许用户直接通过API进行相关的应用创建,任务提交执行等操作,攻击者可通过未授权创建Application从而达到rce的效果。
相关漏洞推荐 hadoop-yarn-rpc-rce: Hadoop Yarn RPC RCE POC hadoop-yarn-unauth: Hadoop Yarn Unauth POC hadoop-unauth-rce: Apache Hadoop YARN ResourceManager - Remote Code Execution POC yarn-resourcemanager-rce: Apache Hadoop YARN ResourceManager - Remote Code Execution Hadoop Yarn RPC 未授权RCE PoC Hadoop YARN ResourceManager 未授权访问 Hadoop_YARN_ResourceManager log文件未授权访问 Hadoop YARN ResourceManager-远程命令执行