CVE-2018-11765

EUVD-2021-0868
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
apachehadoop
2.8.0 ≤
𝑥
≤ 2.8.5
apachehadoop
2.9.0 ≤
𝑥
≤ 2.9.2
apachehadoop
3.0.0
apachehadoop
3.0.0:alpha2
𝑥
= Vulnerable software versions
References