PT-2020-8522 · Apache · Apache Hadoop
Jon-Wei
·
Published
2020-09-30
·
Updated
2021-04-30
·
CVE-2018-11765
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Hadoop versions 2.8.0 through 2.8.5
Apache Hadoop versions 2.9.0 through 2.9.2
Apache Hadoop versions 3.0.0-alpha2 through 3.0.0
Description:
The issue allows any user to access certain servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
Recommendations:
For Apache Hadoop versions 2.8.0 through 2.8.5, consider enabling SPNEGO through HTTP to mitigate the risk.
For Apache Hadoop versions 2.9.0 through 2.9.2, consider enabling SPNEGO through HTTP to mitigate the risk.
For Apache Hadoop versions 3.0.0-alpha2 through 3.0.0, consider enabling SPNEGO through HTTP to mitigate the risk.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Hadoop