CVE-2018-11767: High severity apache hadoop vulnerability
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11767?
CVE-2018-11767 is a vulnerability in Apache Hadoop versions 2.7.5 to 2.7.6, 2.8.3 to 2.8.4, and 2.9.0 to 2.9.1 that can result in KMS incorrectly blocking users or granting access to users.
How does CVE-2018-11767 affect Apache Hadoop?
CVE-2018-11767 affects Apache Hadoop by incorrectly blocking or granting access to users if the system uses non-default group mapping mechanisms.
What is the severity of CVE-2018-11767?
CVE-2018-11767 has a severity rating of high with a CVSS score of 7.4.
Which versions of Apache Hadoop are affected by CVE-2018-11767?
CVE-2018-11767 affects Apache Hadoop versions 2.7.5 to 2.7.6, 2.8.3 to 2.8.4, and 2.9.0 to 2.9.1.
How can I fix CVE-2018-11767 in Apache Hadoop?
To fix CVE-2018-11767 in Apache Hadoop, it is recommended to upgrade to a patched version of the software.