CVE-2018-11764
published 2020-10-21CVE-2018-11764: Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.37%
81.8th percentile
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_apache8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hadoop: privilege escalation in web endpoint
vendor_redhat·2020-10-21·CVSS 8.8
CVE-2018-11764 [HIGH] CWE-287 hadoop: privilege escalation in web endpoint
hadoop: privilege escalation in web endpoint
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.
A flaw was found in Apache Hadoop, where the Web endpoint authentication check is broken. This flaw allows authenticated users to impersonate any user even if no proxy user is configured.
Package: hadoop (Red Hat Fuse 7) - Not affected
Package: hadoop (Red Hat Integration Camel K 1) - Not affected
Package: hadoop-core (Red Hat JBoss Data Grid 7) - Not affected
Package: hadoop-core (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: hadoop-core (Red Hat JBoss Fuse 6) - Not affected
Package: openshift4/ose-metering-hadoop (Red Hat OpenShift Con
Apache
Apache hadoop: CVE-2018-11764
vendor_apache·CVSS 8.8
CVE-2018-11764 [HIGH] Apache hadoop: CVE-2018-11764
Apache hadoop: CVE-2018-11764
Web endpoint authentication check is broken. Authenticated users may impersonate any user even if no proxy user is configured.
GHSA
Authentication bypass in Apache Hadoop
ghsa·2022-02-10
CVE-2018-11764 [HIGH] CWE-306 Authentication bypass in Apache Hadoop
Authentication bypass in Apache Hadoop
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.
OSV
Authentication bypass in Apache Hadoop
osv·2022-02-10
CVE-2018-11764 [HIGH] Authentication bypass in Apache Hadoop
Authentication bypass in Apache Hadoop
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/r790ad0a049cde713b93589ecfd4dd2766fda0fc6807eedb6cf69f5c1%40%3Cgeneral.hadoop.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20201103-0003/https://lists.apache.org/thread.html/r790ad0a049cde713b93589ecfd4dd2766fda0fc6807eedb6cf69f5c1%40%3Cgeneral.hadoop.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20201103-0003/
2020-10-21
Published