PT-2020-8522 · Apache · Apache Hadoop

Jon-Wei

·

Published

2020-09-30

·

Updated

2021-04-30

·

CVE-2018-11765

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Hadoop versions 2.8.0 through 2.8.5 Apache Hadoop versions 2.9.0 through 2.9.2 Apache Hadoop versions 3.0.0-alpha2 through 3.0.0
Description: The issue allows any user to access certain servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
Recommendations: For Apache Hadoop versions 2.8.0 through 2.8.5, consider enabling SPNEGO through HTTP to mitigate the risk. For Apache Hadoop versions 2.9.0 through 2.9.2, consider enabling SPNEGO through HTTP to mitigate the risk. For Apache Hadoop versions 3.0.0-alpha2 through 3.0.0, consider enabling SPNEGO through HTTP to mitigate the risk.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11765
GHSA-RHH9-CM65-3W54

Affected Products

Apache Hadoop