In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
2021-01-26T18:16:10.207
2024-11-21T05:40:45.863
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | hadoop | ≤ 2.10.0 | Yes |
Application | apache | hadoop | ≤ 3.1.3 | Yes |
Application | apache | hadoop | ≤ 3.2.1 | Yes |
Application | apache | solr | 8.6.0 | Yes |
Application | apache | solr | 8.6.2 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 | Yes |