CVE-2018-11765
30.09.2020, 18:15
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.Enginsight
Vendor | Product | Version |
---|---|---|
apache | hadoop | 2.8.0 ≤ 𝑥 ≤ 2.8.5 |
apache | hadoop | 2.9.0 ≤ 𝑥 ≤ 2.9.2 |
apache | hadoop | 3.0.0 |
apache | hadoop | 3.0.0:alpha2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References