CVE-2018-11765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/09/2020
Last modified:
07/11/2023

Description

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.5 (including)
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.2 (including)
cpe:2.3:a:apache:hadoop:3.0.0:-:*:*:*:*:*:*
cpe:2.3:a:apache:hadoop:3.0.0:alpha2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools