PT-2021-12856 · Apache · Apache Hadoop

Published

2021-01-26

·

Updated

2024-03-06

·

CVE-2020-9492

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache Hadoop versions 2.0.0-alpha through 2.10.0 Apache Hadoop versions 3.0.0-alpha1 through 3.1.3 Apache Hadoop versions 3.2.0 through 3.2.1
Description: The WebHDFS client in Apache Hadoop might send an SPNEGO authorization header to a remote URL without proper verification.
Recommendations: For Apache Hadoop versions 2.0.0-alpha through 2.10.0, update to a version outside of this range to resolve the issue. For Apache Hadoop versions 3.0.0-alpha1 through 3.1.3, update to a version outside of this range to resolve the issue. For Apache Hadoop versions 3.2.0 through 3.2.1, update to a version outside of this range to resolve the issue.

Fix

Improper Privilege Management

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-SOLR-2020-9492
CVE-2020-9492
GHSA-F8VC-WFC8-HXQH
OESA-2021-1201

Affected Products

Apache Hadoop