Lucene search

K
osvGoogleOSV:GHSA-4FH8-PM7G-PMXQ
HistoryFeb 10, 2022 - 8:28 p.m.

Authentication bypass in Apache Hadoop

2022-02-1020:28:06
Google
osv.dev
11
apache hadoop
authentication
bypass
web endpoint

EPSS

0.001

Percentile

33.5%

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.

EPSS

0.001

Percentile

33.5%

Related for OSV:GHSA-4FH8-PM7G-PMXQ