HI,

I'm new to Hadoop, so sorry for any inappropriate content.

While reading the Hadoop source code, I noticed that in non-secure mode,
Hadoop allows a user to send almost arbitrary strings as the user name.

After some basic experiments, it seems that a user can interfere with the
NodeManager in this way, even with LCE as the container executor.

Is this part of the "if want security, use security mode" thing? Or is
there a plan to fix it?

Thanks for any information.

Bo Bao

Reply via email to