Security Advisory

CVE-2018-11765

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-09-30 17:02:20
Last updated 2024-08-05 08:17:09
Assigner apache
CVSS score not scored
State PUBLISHED

Description

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.