CVE-2017-7669
HighAdvisory
Published 17 May 2022In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.018
- 77th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 18
- of 17,781 indexed, latest versions
- Container images
- 12
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 12 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| hadoop-commonmaven | 2.7.0, 2.7.3, 2.7.4, 2.7.5+1 more | 2.8.1 | 12 |
- OSV records
- GHSA-h24p-qwf4-84q8
Charts affected
18 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| sparkmicrosoft | 1.0.4 | 1 of 3See more | 13,738 |
| hdfsdmwm-bigdataVerified publisher | 1.0.1 | 1 of 2See more | 7,948 |
| hivedmwm-bigdataVerified publisher | 0.1.6 | 4 of 5See more | 20,837 |
| ignitecloudnativeapp | 1.0.0 | 1 of 1See more | 7,891 |
| hbasedmwm-bigdataVerified publisher | 0.1.6 | 3 of 5See more | 13,392 |
| hive-metastoredmwm-bigdataVerified publisher | 0.1.3 | 1 of 2See more | 6,882 |
| opentsdbdmwm-bigdataVerified publisher | 0.1.7 | 3 of 6See more | 17,511 |
| hbasegradiant-bigdataVerified publisher | 0.1.6 | 3 of 5See more | 13,392 |
| chart-app-vidapp-vid-chartVerified publisher | 0.0.7 | 1 of 2See more | 8,866 |
| spark-history-servercloudnativeapp | 1.0.0 | 1 of 3See more | 14,066 |
| spark-standalonedmwm-bigdataVerified publisher | 0.1.0 | 1 of 2See more | 6,147 |
| spark-shuffleduyet | 0.2.0 | 1 of 1See more | 5,639 |
| hdfsgradiant-bigdataVerified publisher | 0.1.10 | 2 of 2See more | 7,073 |
| hivegradiant-bigdataVerified publisher | 0.1.6 | 4 of 5See more | 20,837 |
| hive-metastoregradiant-bigdataVerified publisher | 0.1.3 | 1 of 2See more | 6,882 |
| opentsdbgradiant-bigdataVerified publisher | 0.1.7 | 3 of 6See more | 17,511 |
| spark-standalonegradiant-bigdataVerified publisher | 0.1.0 | 1 of 2See more | 6,147 |
| pinotinseefrlab | 0.2.0 | 1 of 2See more | 10,777 |
Container images carrying it
12 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| marcelmay/ | 6292c0a41ffa | hadoop-common | 2.8.1 | 8 |
| gradiant/ | 3b28784ba41f | hadoop-common | 2.8.1 | 7 |
| bde2020/ | 620267768985 | hadoop-common | 2.8.1 | 4 |
| gradiant/ | a1ee6de94c04 | hadoop-common | 2.8.1 | 4 |
| gradiant/ | aae4f8a21f8b | hadoop-common | 2.8.1 | 2 |
| gradiant/ | 97657d56e927 | hadoop-common | 2.8.1 | 2 |
| apacheignite/ | d7deab68b8fa | hadoop-common | 2.8.1 | 1 |
| apachepinot/ | 0018bb04ced7 | hadoop-common | 2.8.1 | 1 |
| dbanda/ | 0ca125e68e53 | hadoop-common | 2.8.1 | 1 |
| fimperato/ | 604012b77841 | hadoop-common | 2.8.1 | 1 |
| lightbend/ | 0bedf37f428a | hadoop-common | 2.8.1 | 1 |
| snappydatainc/ | fd4b2070466f | hadoop-common | 2.8.1 | 1 |