Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29153
HistoryJan 27, 2021 - 6:24 a.m.

Information Disclosure

2021-01-2706:24:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
hadoop-hdfs-client
information disclosure
authentication
spnego
network traffic
server access

EPSS

0.018

Percentile

88.1%

hadoop-hdfs-client is vulnerable to information disclosure. The application allows the sending of authentication credentials over an insecure HTTP channel. An attacker is able to intercept the network traffic and obtain the SPNEGO authorization header and gain access to the server.

References

EPSS

0.018

Percentile

88.1%