cbcvebase.
CVE-2020-17533
published 2020-12-29

CVE-2020-17533: Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before permitting…

PriorityP348high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
3.65%
88.3th percentile
Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before permitting an authenticated user to perform certain administrative operations. Specifically, the return values of the 'canFlush' and 'canPerformSystemActions' security functions are not checked in some instances, therefore allowing an authenticated user with insufficient permissions to perform the following actions: flushing a table, shutting down Accumulo or an individual tablet server, and setting or removing system-wide Accumulo configuration properties.

Affected

4 ranges
VendorProductVersion rangeFixed in
apacheaccumulo
apacheaccumulo1.5.0 – 1.10.0
apache_software_foundationapache_accumulo
apache_software_foundationapache_accumulo>= 1.5.0 < Apache Accumulo*Apache Accumulo*

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.