← back
CVE-2018-11765

CVE-2018-11765

EPSS 5.1%
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
Affected products
n/a · Apache Hadoop

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →