Severity: 
    CVSS 4.0: 4.8 (medium) 
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected versions:

- Apache YuniKorn before 1.10.0

Description:

Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user 
annotation by setting a secondary label on the pod. If the pod has the label 
'app=yunikorn' the checks limiting the user annotation content are not run. The 
label is used to identify the YuniKorn application itself in the deployments.


The bypass allows any user to specify an arbitrary user info annotation. The 
arbitrary user information could allow access to a queue that the user normally 
would not have access to. Quota usage for the queue might be impacted if the 
application runs in the incorrect queue. User based quota enforcement is also 
based on the user annotation. User quota tracking could be side stepped even if 
the application runs in the correct queue.




Users are recommended to upgrade to version 1.10.0, which fixes this issue.

This issue is being tracked as YUNIKORN-3472 

Credit:

[email protected] (finder)

References:

https://yunikorn.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-97146
https://issues.apache.org/jira/browse/YUNIKORN-3472

Reply via email to