CVE-2019-0212
published 2019-03-28CVE-2019-0212: In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server…
PriorityP349high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
3.85%
89.0th percentile
In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_hbase | — | — |
| apache | apache_hbase | — | — |
| apache | hbase | 2.0.0 – 2.0.4 | — |
| apache | hbase | 2.1.0 – 2.1.3 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Authorization in org.apache.hbase:hbase
osv·2019-04-02
CVE-2019-0212 [HIGH] Improper Authorization in org.apache.hbase:hbase
Improper Authorization in org.apache.hbase:hbase
In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.
GHSA
Improper Authorization in org.apache.hbase:hbase
ghsa·2019-04-02
CVE-2019-0212 [HIGH] CWE-285 Improper Authorization in org.apache.hbase:hbase
Improper Authorization in org.apache.hbase:hbase
In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.
Red Hat
hbase: Apache HBase REST Server incorrect user authorization
vendor_redhat·2019-03-27·CVSS 7.5
CVE-2019-0212 [HIGH] CWE-285 hbase: Apache HBase REST Server incorrect user authorization
hbase: Apache HBase REST Server incorrect user authorization
In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.
Package: camel-hbase (Red Hat Fuse 7) - Not affected
Package: camel-hbase (Red Hat JBoss Fuse 6) - Out of support scope
Package: camel-hbase (Red Hat JBoss Fuse Service Works 6) - Out of support scope
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0212 hbase: Apache HBase REST Server incorrect user authorization
bugzilla·2019-04-04·CVSS 7.5
CVE-2019-0212 [HIGH] CVE-2019-0212 hbase: Apache HBase REST Server incorrect user authorization
CVE-2019-0212 hbase: Apache HBase REST Server incorrect user authorization
In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.
References:
https://www.openwall.com/lists/oss-security/2019/03/27/3
Discussion:
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
* Red
Bugzilla
CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
bugzilla·2018-06-01·CVSS 6.1
CVE-2018-11627 [MEDIUM] CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
It was found that Sinatra is vulnerable to an XSS via the 400 Bad Request page that occurs upon a params parser exception.
Upstream issue:
https://github.com/sinatra/sinatra/issues/1428
Introduced by:
https://github.com/sinatra/sinatra/commit/8f8df53ff29938ace79b31097c27d9cdac803b44
Upstream patch:
https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71a
Discussion:
Created rubygem-sinatra tracking bugs for this issue:
Affects: fedora-all [bug 1585221]
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.10
Via RHSA-2019:0212 https://access.redhat.com/errata/RHSA-2019:0212
---
This issue has been addressed in the following products:
CloudForms Ma
http://www.openwall.com/lists/oss-security/2019/03/27/3http://www.securityfocus.com/bid/107624https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/66535e15007cda8f9308eec10e12ffe349e0b8b55e56ec6ee02b71d2%40%3Cdev.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2019/03/27/3http://www.securityfocus.com/bid/107624https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/66535e15007cda8f9308eec10e12ffe349e0b8b55e56ec6ee02b71d2%40%3Cdev.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
2019-03-28
Published