Vulnerability Description
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Hadoop | >= 2.8.0, <= 2.8.5 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r17d94d132b207dad221595fd8b8b18628f5f5ec7e3
- https://lists.apache.org/thread.html/r2c7f899911a04164ed1707083fcd4135f8427e0477Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r46447f38ea8c89421614e9efd7de5e656186d35e10
- https://lists.apache.org/thread.html/r4dddf1705dbedfa94392913b2dad1cd2d1d89040fa
- https://lists.apache.org/thread.html/r74825601e93582167eb7cdc2f764c74c9c6d8006fa
- https://lists.apache.org/thread.html/r79b15c5b66c6df175d01d7560adf0cd5c369129b9a
- https://lists.apache.org/thread.html/rb21df54a4e39732ce653d2aa5672e36a792b59eb67
- https://lists.apache.org/thread.html/rb241464d83baa3749b08cd3dabc8dba70a9a9027ed
- https://lists.apache.org/thread.html/rbe25cac0f499374f8ae17a4a44a8404927b56de28d
- https://lists.apache.org/thread.html/reea5eb8622afbfbfca46bc758f79db83d90a3263a9
- https://lists.apache.org/thread.html/rf9dfa8b77585c9227db9637552eebb2ab029255a0d
- https://security.netapp.com/advisory/ntap-20201016-0005/
- https://lists.apache.org/thread.html/r17d94d132b207dad221595fd8b8b18628f5f5ec7e3
- https://lists.apache.org/thread.html/r2c7f899911a04164ed1707083fcd4135f8427e0477Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r46447f38ea8c89421614e9efd7de5e656186d35e10
FAQ
What is CVE-2018-11765?
CVE-2018-11765 is a vulnerability with a CVSS score of 7.5 (HIGH). In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HT...
How severe is CVE-2018-11765?
CVE-2018-11765 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11765?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Hadoop.