cbcvebase.
CVE-2018-11768
published 2019-10-04

CVE-2018-11768: In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in…

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop
apachehadoop2.2.0 – 2.8.4
apachehadoop2.9.0 – 2.9.1
apachehadoop3.0.1 – 3.0.3
apachehadoop3.1.0 – 3.1.1
phpmyadminphpmyadmin>= 0 < 4:4.6.6-5ubuntu0.54:4.6.6-5ubuntu0.5

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv6.5MEDIUM