RULE(RULE ID:330454)

Rule General Information
Release Date: 2020-06-24
Rule Name: Hadoop YARN ResourceManager Unauthenticated Command Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The Apache Hadoop YARN ResourceManager running on the remote host is allowing unauthenticated users to create and execute applications. An unauthenticated, remote attacker can exploit this, via a specially crafted HTTP request, to potentially execute arbitrary code, subject to the user privileges of the executing node.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Mac OS, Others
Reference:
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.