Security Advisory

CVE-2018-11764

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-10-21 18:13:56
Last updated 2024-08-05 08:17:09
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.