Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11764

Опубликовано: 21 окт. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.

A flaw was found in Apache Hadoop, where the Web endpoint authentication check is broken. This flaw allows authenticated users to impersonate any user even if no proxy user is configured.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7hadoopNot affected
Red Hat Integration Camel K 1hadoopNot affected
Red Hat JBoss Data Grid 7hadoop-coreNot affected
Red Hat JBoss Data Virtualization 6hadoop-coreOut of support scope
Red Hat JBoss Fuse 6hadoop-coreNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1890161hadoop: privilege escalation in web endpoint

EPSS

Процентиль: 40%
0.00185
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.

CVSS3: 8.8
debian
больше 5 лет назад

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alp ...

CVSS3: 8.8
github
почти 4 года назад

Authentication bypass in Apache Hadoop

EPSS

Процентиль: 40%
0.00185
Низкий

8.8 High

CVSS3