Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2018-11765

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:P/I:N/A:N
Software From Fixed in
apache / hadoop 3.0.0-alpha2 3.0.0-alpha2.x
apache / hadoop 3.0.0 3.0.0.x
apache / hadoop 2.8.0 2.8.5.x
apache / hadoop 2.9.0 2.9.2.x
org.apache.hadoop / hadoop-main 3.0.0-alpha2 3.0.1
org.apache.hadoop / hadoop-main 2.9.0 2.9.3
org.apache.hadoop / hadoop-main 2.8.0 2.8.6