In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2020-09-30T17:02:20
Updated: 2024-08-05T08:17:09.112Z
Reserved: 2018-06-05T00:00:00
Link: CVE-2018-11765
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-30T18:15:15.477
Modified: 2023-11-07T02:51:45.280
Link: CVE-2018-11765
Redhat