CVE-2018-11765

Description

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.147

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-11764,CVE-2018-11765 are fixed in Apache - hadoop-main 3.0.1Windows
Vulnerabilities CVE-2018-11765 are fixed in Apache - hadoop-main 2.9.3Windows
Vulnerabilities CVE-2018-11765 are fixed in Apache - hadoop-main 2.8.6Windows
Vulnerabilities CVE-2018-11764,CVE-2018-11765 are fixed in Apache - hadoop-main for Linux 3.0.1Linux
Vulnerabilities CVE-2018-11765 are fixed in Apache - hadoop-main for Linux 2.9.3Linux
Vulnerabilities CVE-2018-11765 are fixed in Apache - hadoop-main for Linux 2.8.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234