Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-9492

Опубликовано: 26 янв. 2021
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.

A flaw was found in Apache hadoop. The WebHDFS client can send a SPNEGO authorization header to a remote URL without proper verification which could lead to an access restriction bypass. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

While OpenShift Container Platform (OCP) does package a vulnerable version of hadoop-hdfs-client in the hadoop and hive containers, the HDFS storage back-end is not enabled by default and is largely undocumented/unsupported. However, as it still can be enabled by using the configuration option unsupportedFeatures.enabledHDFS, the vulnerability has been rated Moderate for OCP. In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of hadoop package. Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix. This may be fixed in the future. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7hadoop-hdfs-clientFix deferred
Red Hat JBoss Enterprise Application Platform 7hadoop-hdfs-clientNot affected
Red Hat JBoss Fuse 6hadoop-hdfs-clientOut of support scope
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hiveWill not fix
RHAF Camel-K 1.8hadoop-hdfs-clientFixedRHSA-2022:640709.09.2022
RHINT Camel-Q 2.7hadoop-hdfs-clientFixedRHSA-2022:560619.07.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1925237hadoop: WebHDFS client might send SPNEGO authorization header

EPSS

Процентиль: 31%
0.00115
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.

CVSS3: 8.8
debian
около 5 лет назад

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alph ...

CVSS3: 8.8
github
почти 4 года назад

Improper Privilege Management in Apache Hadoop

EPSS

Процентиль: 31%
0.00115
Низкий

8.8 High

CVSS3