In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.
2019-03-21T16:00:11.780
2024-11-21T03:43:59.433
Modified
CVSSv3.0: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | hadoop | ≤ 2.7.6 | Yes |
Application | apache | hadoop | ≤ 2.8.4 | Yes |
Application | apache | hadoop | ≤ 2.9.1 | Yes |