Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8xr-4v2c-rvgp

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

High severity vulnerability that affects org.apache.hbase:hbase

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

Пакеты

Наименование

org.apache.hbase:hbase

maven
Затронутые версииВерсия исправления

>= 0.98, <= 0.98.12.0

0.98.12.1

Наименование

org.apache.hbase:hbase

maven
Затронутые версииВерсия исправления

>= 1.0.0, <= 1.0.1.0

1.0.1.1

Наименование

org.apache.hbase:hbase

maven
Затронутые версииВерсия исправления

= 1.1.0

1.1.0.1

EPSS

Процентиль: 84%
0.02143
Низкий

7.3 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

redhat
больше 10 лет назад

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

CVSS3: 7.3
nvd
около 10 лет назад

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

EPSS

Процентиль: 84%
0.02143
Низкий

7.3 High

CVSS3

Дефекты

CWE-284