Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run the bootstrap script and RPM files with the fix provided in the location below.
The Secret Agent component in Amazon EMR creates a keytab file with Kerberos credentials and places it in the /tmp/ directory. This directory is typically shared among system users. A local user with access to /tmp/ and an additional account can read the keytab file and then decrypt the keys contained in it (CWE-257: storage of password in reversibly encrypted form). This enables Kerberos identity hijacking and privilege escalation.
An attacker with local access can decrypt Kerberos credentials and escalate privileges to a higher level, potentially gaining access to EMR cluster resources protected by Kerberos.
Amazon EMR should be updated to version 7.5 or higher. For versions in the range 6.10–7.4, the vendor recommends running the provided bootstrap script and RPM files with the patch, according to the information contained in security bulletin AWS-2025-017 (https://aws.amazon.com/security/security-bulletins/AWS-2025-017/).
Amazon EMR in versions 6.10 to 7.4 and earlier using the Secret Agent component with Kerberos support.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X