Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11768

Опубликовано: 04 окт. 2019
Источник: redhat
CVSS3: 7.5

Описание

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.

Отчет

Hadoop is included in OpenShift Container Platform 4.2 and later as part of the metering operator. It's an optional feature that is not installed by default.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7hadoopFix deferred
Red Hat JBoss Data Grid 7hadoop-commonNot affected
Red Hat JBoss Data Virtualization 6hadoop-coreOut of support scope
Red Hat JBoss Fuse 6hadoop-coreOut of support scope
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopWill not fix
Red Hat Satellite 5nutchOut of support scope
Red Hat Satellite 5spacewalk-searchOut of support scope
Red Hat Storage 3rhs-hadoopNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1764650hadoop: user/group information corruption through fsimage storing and reading

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.

CVSS3: 7.5
debian
больше 6 лет назад

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1 ...

CVSS3: 7.5
github
около 6 лет назад

user/group information can be corrupted across storing in fsimage and reading back from fsimage

7.5 High

CVSS3