Apache · Apache Hadoop · CVE-2018-11765
Name of the Vulnerable Software and Affected Versions:
Apache Hadoop versions 2.8.0 through 2.8.5
Apache Hadoop versions 2.9.0 through 2.9.2
Apache Hadoop versions 3.0.0-alpha2 through 3.0.0
Description:
The issue allows any user to access certain servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
Recommendations:
For Apache Hadoop versions 2.8.0 through 2.8.5, consider enabling SPNEGO through HTTP to mitigate the risk.
For Apache Hadoop versions 2.9.0 through 2.9.2, consider enabling SPNEGO through HTTP to mitigate the risk.
For Apache Hadoop versions 3.0.0-alpha2 through 3.0.0, consider enabling SPNEGO through HTTP to mitigate the risk.