CVE-2018-8025
published 2018-06-27CVE-2018-8025: CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could…
PriorityP345high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.76%
75.3th percentile
CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would be considered a different user or an unauthenticated user would be treated as an authenticated user. https://issues.apache.org/jira/browse/HBASE-20664 implements a fix for this issue. It has been fixed in versions: 1.2.6.1, 1.3.2.1, 1.4.5, 2.0.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hbase | <= 2.0.0 | — |
| apache | hbase | — | — |
| apache_software_foundation | apache_hbase | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Race condition in org.apache.hbase:hbase-thrift
ghsa·2018-10-18
CVE-2018-8025 [HIGH] CWE-362 Race condition in org.apache.hbase:hbase-thrift
Race condition in org.apache.hbase:hbase-thrift
An issue in Apache HBase affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would be considered a different user or an unauthenticated user would be treated as an authenticated user. https://issues.apache.org/jira/browse/HBASE-20664 implements a fix for this issue. It has been fixed in versions: 1.2.6.1, 1.3.2.1, 1.4.5, 2.0.1.
OSV
Race condition in org.apache.hbase:hbase-thrift
osv·2018-10-18
CVE-2018-8025 [HIGH] Race condition in org.apache.hbase:hbase-thrift
Race condition in org.apache.hbase:hbase-thrift
An issue in Apache HBase affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would be considered a different user or an unauthenticated user would be treated as an authenticated user. https://issues.apache.org/jira/browse/HBASE-20664 implements a fix for this issue. It has been fixed in versions: 1.2.6.1, 1.3.2.1, 1.4.5, 2.0.1.
Red Hat
hbase: race-condition in "Thrift 1" API server
vendor_redhat·2018-05-31·CVSS 8.1
CVE-2018-8025 [HIGH] CWE-362 hbase: race-condition in "Thrift 1" API server
hbase: race-condition in "Thrift 1" API server
CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would be considered a different user or an unauthenticated user would be treated as an authenticated user. https://issues.apache.org/jira/browse/HBASE-20664 implements a fix for this issue. It has been fixed in versions: 1.2.6.1, 1.3.2.1, 1.4.5, 2.0.1.
Package: camel-hbase (Red Hat Fuse 7) - Not affected
Package: camel-hbase (Red Hat JBoss Fuse 6) - Not affected
Package: camel-hbase (Red Hat JBoss Fuse Service Works 6) - Not affected
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104554https://lists.apache.org/thread.html/a919e38f587c714c386a01d40fc8f45bd4219a65aaf2dc0bb4eccc96%40%3Cdev.hbase.apache.org%3Ehttp://www.securityfocus.com/bid/104554https://lists.apache.org/thread.html/a919e38f587c714c386a01d40fc8f45bd4219a65aaf2dc0bb4eccc96%40%3Cdev.hbase.apache.org%3E
2018-06-27
Published