PT-2018-13217 · Mapr · Mapr Converged Data Platform+2

Publicado

2018-08-23

·

Atualizado

2019-10-03

·

CVE-2018-15804

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MapR Converged Data Platform versions 6.x and earlier MapR-XD versions 6.x and earlier
Description An issue in the MapR File System allows MapR ticket credentials to become compromised under certain conditions, enabling a user to escalate their privileges and impersonate any other user, including cluster administrators. This issue affects users who have enabled security on the MapR platform.
Recommendations For MapR Converged Data Platform versions 6.x and earlier, update to a version that includes the fix, such as mapr-patch-5.2.1.42646.GA-20180731093831, mapr-patch-5.2.2.44680.GA-20180802011430, mapr-patch-6.0.0.20171109191718.GA-20180802011420, or mapr-patch-6.0.1.20180404222005.GA-20180806214919. For MapR-XD versions 6.x and earlier, update to a version that includes the fix, such as mapr-patch-5.2.1.42646.GA-20180731093831, mapr-patch-5.2.2.44680.GA-20180802011430, mapr-patch-6.0.0.20171109191718.GA-20180802011420, or mapr-patch-6.0.1.20180404222005.GA-20180806214919.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-15804

Produtos afetados

Mapr Converged Data Platform
Mapr File System
Mapr-Xd