Lucene search

K
osvGoogleOSV:CVE-2018-11765
HistorySep 30, 2020 - 6:15 p.m.

CVE-2018-11765

2020-09-3018:15:15
Google
osv.dev
4
apache hadoop
insecure access
kerberos authentication
spnego
vulnerability

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

67.9%

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

References

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

67.9%