Lucene search

K
osvGoogleOSV:GHSA-RHH9-CM65-3W54
HistoryApr 30, 2021 - 5:29 p.m.

Improper Authentication in Apache Hadoop

2021-04-3017:29:30
Google
osv.dev
14
apache hadoop
authentication
kerberos
spnego
servlets

EPSS

0.003

Percentile

67.9%

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

References

EPSS

0.003

Percentile

67.9%