Back to Vulnerability Directory
HIGHFixed upstream

CVE-2018-8025

Apache HBase: Thrift 1 server over HTTP can apply one user's session to another

Technology

Apache HBase

CVSS Score

8.1 / 10.0

Affected Versions

All Apache HBase 1.x and 2.x lines released before the fix, except 1.0.0

Upstream Fix

1.2.6.1, 1.3.2.1, 1.4.5, 2.0.1

Published

June 27, 2018

OSSeva Coverage

Fixed upstream

Description

A race condition in the optional Thrift 1 API server, when it runs over HTTP, can apply an authenticated session to the wrong user, so one authenticated user is treated as another or an unauthenticated user is treated as authenticated. HBASE-20664 fixed it.

Upstream record: NVD · CVE.org

Is your Apache HBase deployment affected?

If you're running All Apache HBase 1.x and 2.x lines released before the fix, except 1.0.0, you need this patch. Book a discovery call to get covered.