Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11765

Опубликовано: 28 сент. 2020
Источник: redhat
CVSS3: 6.5

Описание

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

Меры по смягчению последствий

Users should upgrade to Apache Hadoop 2.10.0, 3.0.1 or upper. If it is not possible and affected version of Apache Hadoop is used, SPNEGO through HTTP should be enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7hadoop-coreNot affected
Red Hat JBoss Data Grid 7hadoop-coreOut of support scope
Red Hat JBoss Data Virtualization 6hadoop-coreOut of support scope
Red Hat JBoss Fuse 6hadoop-coreOut of support scope
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1883549hadoop: Potential information disclosure in Hadoop Web interfaces

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

CVSS3: 7.5
debian
больше 5 лет назад

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 ...

CVSS3: 7.5
github
почти 5 лет назад

Improper Authentication in Apache Hadoop

6.5 Medium

CVSS3