Back to Vulnerability Directory
HIGHFixed upstream
CVE-2019-0212
Apache HBase: REST server applies its own permissions instead of the end user's
Technology
Apache HBase
CVSS Score
7.5 / 10.0
Affected Versions
Apache HBase 2.0.0 to 2.0.4, 2.1.0 to 2.1.3
Upstream Fix
2.0.5, 2.1.4
Published
March 28, 2019
OSSeva Coverage
Fixed upstream
Description
When HBase uses Kerberos authentication with authorization enabled and the REST server uses SPNEGO, requests sent to the REST server run with the REST server's permissions rather than those of the end user. The issue does not extend beyond the REST server; the advisory's mitigation was to stop the REST server until the upgrade.
Is your Apache HBase deployment affected?
If you're running Apache HBase 2.0.0 to 2.0.4, 2.1.0 to 2.1.3, you need this patch. Book a discovery call to get covered.