← Back

CVE-2018-11765

nvd nist
Published: Sep 30, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

Affected (4)

Products: Apache: Hadoop
1 product
Hadoop
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.8.0 to 2.8.5
From 2.9.0 to 2.9.2
Version 3.0.0
Version 3.0.0 alpha2

References (24)

Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.