CVE-2018-11768

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
apachehadoop
2.2.0 ≤
𝑥
≤ 2.8.4
apachehadoop
2.9.0 ≤
𝑥
≤ 2.9.1
apachehadoop
3.0.1 ≤
𝑥
≤ 3.0.3
apachehadoop
3.1.0 ≤
𝑥
≤ 3.1.1
apachehadoop
2.0.0
apachehadoop
2.0.0:alpha
apachehadoop
2.0.1
apachehadoop
2.0.1:alpha
apachehadoop
2.0.2
apachehadoop
2.0.2:alpha
apachehadoop
2.0.3
apachehadoop
2.0.3:alpha
apachehadoop
2.0.4
apachehadoop
2.0.4:alpha
apachehadoop
2.0.5
apachehadoop
2.0.5:alpha
apachehadoop
2.0.6
apachehadoop
2.0.6:alpha
apachehadoop
2.1.0
apachehadoop
2.1.0:beta
apachehadoop
2.1.1:beta
apachehadoop
3.0.0
apachehadoop
3.0.0:alpha1
apachehadoop
3.0.0:alpha2
apachehadoop
3.0.0:alpha3
apachehadoop
3.0.0:alpha4
apachehadoop
3.0.0:beta1
𝑥
= Vulnerable software versions
References