Back to Vulnerability Directory
HIGHFixed upstream

CVE-2019-0212

Apache HBase: REST server applies its own permissions instead of the end user's

Technology

Apache HBase

CVSS Score

7.5 / 10.0

Affected Versions

Apache HBase 2.0.0 to 2.0.4, 2.1.0 to 2.1.3

Upstream Fix

2.0.5, 2.1.4

Published

March 28, 2019

OSSeva Coverage

Fixed upstream

Description

When HBase uses Kerberos authentication with authorization enabled and the REST server uses SPNEGO, requests sent to the REST server run with the REST server's permissions rather than those of the end user. The issue does not extend beyond the REST server; the advisory's mitigation was to stop the REST server until the upgrade.

Upstream record: NVD · CVE.org

Is your Apache HBase deployment affected?

If you're running Apache HBase 2.0.0 to 2.0.4, 2.1.0 to 2.1.3, you need this patch. Book a discovery call to get covered.