Lucene search

K
githubGitHub Advisory DatabaseGHSA-RHH9-CM65-3W54
HistoryApr 30, 2021 - 5:29 p.m.

Improper Authentication in Apache Hadoop

2021-04-3017:29:30
CWE-287
GitHub Advisory Database
github.com
31
apache hadoop
improper authentication
kerberos authentication

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

67.9%

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

Affected configurations

Vulners
Node
org.apache.hadoophadoop-mainRange2.8.02.8.5
OR
org.apache.hadoophadoop-mainRange2.9.02.9.2
OR
org.apache.hadoophadoop-mainRange3.0.0-alpha23.0.0
VendorProductVersionCPE
org.apache.hadoophadoop-main*cpe:2.3:a:org.apache.hadoop:hadoop-main:*:*:*:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

67.9%