Description
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: High
Availability: None
Affected Packages3 packages
▶CVEListV5apache_hadoopApache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, 2.0.0-alpha to 2.8.4 🔴Vulnerability Details
4OSVphpmyadmin vulnerabilities↗2020-11-19 ▶ OSVuser/group information can be corrupted across storing in fsimage and reading back from fsimage↗2019-11-20 ▶ GHSAuser/group information can be corrupted across storing in fsimage and reading back from fsimage↗2019-11-20 ▶ CVEListCVE-2018-11768: In Apache Hadoop 3↗2019-10-04 ▶ 📋Vendor Advisories
2Red Hathadoop: user/group information corruption through fsimage storing and reading↗2019-10-04 ▶ ApacheApache hadoop: CVE-2018-11768↗ ▶ 💬Community
2BugzillaCVE-2018-11768 hadoop: user/group information corruption through fsimage storing and reading [fedora-all]↗2019-10-23 ▶ BugzillaCVE-2018-11768 hadoop: user/group information corruption through fsimage storing and reading↗2019-10-23 ▶