CVE-2018-11765

HIGH

Apache Hadoop 2.8.0-2.8.5, 2.9.0-2.9.2, 3.0.0-alpha2-3.0.0 - Unauthenticated Servlet Access via Kerberos Bypass

Title source: llm
STIX 2.1

Description

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.

References (12)

Core 12
Core References
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201016-0005/

Scores

CVSS v3 7.5
EPSS 0.0115
EPSS Percentile 78.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (3)
apache/hadoop 3.0.0 (2 CPE variants)
apache/hadoop 2.8.0 - 2.8.5
org.apache.hadoop/hadoop-main 3.0.0-alpha2 - 3.0.1Maven
Published Sep 30, 2020
Tracked Since Feb 18, 2026