CVE-2018-11764
EUVD-2022-081021.10.2020, 19:15
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | hadoop | 3.0.0 |
| apache | hadoop | 3.0.0:alpha4 |
| apache | hadoop | 3.0.0:beta1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References