Back to Vulnerability Directory
HIGHFixed upstream

CVE-2018-11765

Apache Hadoop: web servlets reachable without authentication when Kerberos is on but SPNEGO is off

Technology

Apache Hadoop

CVSS Score

7.5 / 10.0

Affected Versions

2.8.0 to 2.8.5; 2.9.0 to 2.9.2; 3.0.0-alpha2 to 3.0.0

Upstream Fix

2.10.0; 3.0.1

Published

September 30, 2020

OSSeva Coverage

Fixed upstream

Description

When Kerberos authentication is enabled and SPNEGO over HTTP is not, any user can access some web servlets without authentication, leading to information disclosure.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 2.8.0 to 2.8.5; 2.9.0 to 2.9.2; 3.0.0-alpha2 to 3.0.0, you need this patch. Book a discovery call to get covered.