CVE-2020-9492: High severity Apache Hadoop vulnerability
A flaw was found in Apache hadoop. The WebHDFS client can send a SPNEGO authorization header to a remote URL without proper verification which could lead to an access restriction bypass. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/hadoopto a version that resolves this vulnerability.Fixed in 3.2.2 - Upgrade
Upgrade
redhat/hadoopto a version that resolves this vulnerability.Fixed in 3.1.4 - Upgrade
Upgrade
redhat/hadoopto a version that resolves this vulnerability.Fixed in 2.10.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-9492?
CVE-2020-9492 is a vulnerability found in Apache Hadoop, which allows the WebHDFS client to send a SPNEGO authorization header to a remote URL without proper verification, leading to an access restriction bypass.
How does CVE-2020-9492 impact data confidentiality and integrity?
CVE-2020-9492 can compromise data confidentiality and integrity as well as system availability.
Which software versions are affected by CVE-2020-9492?
The affected software versions include Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0.
What is the severity level of CVE-2020-9492?
CVE-2020-9492 has a severity level of 8.8 (high).
How can I fix CVE-2020-9492?
To fix CVE-2020-9492, update your Apache Hadoop installation to version 3.2.2, 3.1.4, or 2.10.1.