hadoop-yarn-unauth: Hadoop Yarn Unauth

日期: 2025-09-01 | 影响软件: Hadoop Yarn | POC: 已公开

漏洞描述

app="APACHE-hadoop-YARN"

PoC代码[已公开]

id: hadoop-yarn-unauth

info:
  name: Hadoop Yarn Unauth
  author: p0wd3r,sharecast
  severity: high
  verified: true
  description: |
    app="APACHE-hadoop-YARN"
  tags: hadoop,yarn,unauth
  created: 2024/01/17

rules:
  r0:
    request:
      method: GET
      path: /ws/v1/cluster/info
    expression: |
      response.status == 200 && 
      response.body.bcontains(b"resourceManagerVersionBuiltOn") && 
      response.body.bcontains(b"hadoopVersion")
  r1:
    request:
      method: GET
      path: /ws/v1/cluster/apps/new-application
    expression: response.status == 200 && response.body.bcontains(b"javax.ws.rs.WebApplicationException")
expression: r0() || r1()

相关漏洞推荐