Lucene search

K
osvGoogleOSV:GHSA-C6F9-4PMV-M7M6
HistoryMay 17, 2022 - 2:54 a.m.

Apache Hadoop allows impersonation of arbitrary cluster user accounts

2022-05-1702:54:07
Google
osv.dev
4

0.002 Low

EPSS

Percentile

59.1%

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.

CPENameOperatorVersion
org.apache.hadoop:hadoop-maineq0.23.1

0.002 Low

EPSS

Percentile

59.1%

Related for OSV:GHSA-C6F9-4PMV-M7M6