Vulnerability Description
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Hadoop | >= 2.2.0, <= 2.8.4 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/2067a797b330530a6932f4b08f703b3173253d0a2b7
- https://lists.apache.org/thread.html/2c9cc65864be0058a5d5ed2025dfb9c700bf23d352b
- https://lists.apache.org/thread.html/72ca514e01cd5f08151e74f9929799b4cbe1b6e9e6c
- https://lists.apache.org/thread.html/9b609d4392d886711e694cf40d86f770022baf42a1b
- https://lists.apache.org/thread.html/caacbbba2dcc1105163f76f3dfee5fbd22e0417e078
- https://lists.apache.org/thread.html/ceb16af9139ab0fea24aef935b6321581976887df7a
- https://lists.apache.org/thread.html/ea6d2dfbefab8ebe46be18b05136b83ae53b7866f1b
- https://lists.apache.org/thread.html/f20bb4e055d8394fc525cc7772fb84096f706389043
- https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462
- https://lists.apache.org/thread.html/r02e39d7beb32eebcdbb4b516e95f67d71c90d5d462
- https://lists.apache.org/thread.html/2067a797b330530a6932f4b08f703b3173253d0a2b7
- https://lists.apache.org/thread.html/2c9cc65864be0058a5d5ed2025dfb9c700bf23d352b
- https://lists.apache.org/thread.html/72ca514e01cd5f08151e74f9929799b4cbe1b6e9e6c
- https://lists.apache.org/thread.html/9b609d4392d886711e694cf40d86f770022baf42a1b
- https://lists.apache.org/thread.html/caacbbba2dcc1105163f76f3dfee5fbd22e0417e078
FAQ
What is CVE-2018-11768?
CVE-2018-11768 is a vulnerability with a CVSS score of 7.5 (HIGH). In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
How severe is CVE-2018-11768?
CVE-2018-11768 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11768?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Hadoop.