Lucene search

K
osvGoogleOSV:CVE-2018-11764
HistoryOct 21, 2020 - 7:15 p.m.

CVE-2018-11764

2020-10-2119:15:13
Google
osv.dev
7
web endpoint
authentication
apache hadoop 3.0.0
security issue

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

33.5%

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

33.5%