VDB
Sign up
HIGH8.8

GHSA-4fh8-pm7g-pmxq

Authentication bypass in Apache Hadoop

Quick fix

GHSA-4fh8-pm7g-pmxq — org.apache.hadoop:hadoop-main: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-main

Details

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.hadoop:hadoop-main
Introduced in: 3.0.0-alpha4Fixed in: 3.0.1
Fix# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-main
Maven/org.apache.hadoop:hadoop-main
Introduced in: 3.0.0-beta1Fixed in: 3.0.1
Fix# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-main
Maven/org.apache.hadoop:hadoop-main
Introduced in: 3.0.0Fixed in: 3.0.1
Fix# pom.xml: bump <version>3.0.1</version> for org.apache.hadoop:hadoop-main

References