CVE-2018-11768

CWE-119Buffer Overflow9 documents7 sources
Severity
7.5HIGH
EPSS
1.3%
top 20.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateNov 19

Description

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Mavenorg.apache.hadoop:hadoop-main2.2.02.8.5+2
NVDapache/hadoop2.2.02.8.4+13
CVEListV5apache_hadoopApache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, 2.0.0-alpha to 2.8.4

🔴Vulnerability Details

4
OSV
phpmyadmin vulnerabilities2020-11-19
OSV
user/group information can be corrupted across storing in fsimage and reading back from fsimage2019-11-20
GHSA
user/group information can be corrupted across storing in fsimage and reading back from fsimage2019-11-20
CVEList
CVE-2018-11768: In Apache Hadoop 32019-10-04

📋Vendor Advisories

2
Red Hat
hadoop: user/group information corruption through fsimage storing and reading2019-10-04
Apache
Apache hadoop: CVE-2018-11768

💬Community

2
Bugzilla
CVE-2018-11768 hadoop: user/group information corruption through fsimage storing and reading [fedora-all]2019-10-23
Bugzilla
CVE-2018-11768 hadoop: user/group information corruption through fsimage storing and reading2019-10-23