HIGH8.8
GHSA-4fh8-pm7g-pmxq
Authentication bypass in Apache Hadoop
Quick fix
GHSA-4fh8-pm7g-pmxq — org.apache.hadoop:hadoop-main: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-mainDetails
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.hadoop:hadoop-main
Introduced in:
3.0.0-alpha4Fixed in: 3.0.1Fix
# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-mainMaven/org.apache.hadoop:hadoop-main
Introduced in:
3.0.0-beta1Fixed in: 3.0.1Fix
# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-mainMaven/org.apache.hadoop:hadoop-main
Introduced in:
3.0.0Fixed in: 3.0.1Fix
# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-main