PT-2015-5463 · Apache · Apache Hbase
Enis Söztutar
+1
·
Publicado
2015-12-21
·
Atualizado
2018-10-18
·
CVE-2015-1836
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HBase versions 0.98 through 0.98.12.0
Apache HBase versions 1.0 through 1.0.1.0
Apache HBase versions 1.1 through 1.1.0.0
Description
The issue allows remote attackers to cause a denial of service, obtain sensitive information, or modify data via unspecified client traffic due to incorrect ACLs for ZooKeeper coordination state.
Recommendations
For Apache HBase versions 0.98 through 0.98.12.0, update to version 0.98.12.1 or later.
For Apache HBase versions 1.0 through 1.0.1.0, update to version 1.0.1.1 or later.
For Apache HBase versions 1.1 through 1.1.0.0, update to version 1.1.0.1 or later.
Correção
DoS
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Hbase