CVE-2018-11767

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
21/03/2019
Last modified:
07/11/2023

Description

In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 2.7.5 (including) 2.7.6 (including)
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 2.8.3 (including) 2.8.4 (including)
cpe:2.3:a:apache:hadoop:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.1 (including)