Skip to content
Apache HadoopGHSA-f8vc-wfc8-hxqh

Improper Privilege Management in Apache Hadoop

High8.8CVE-2020-9492 · Published Feb 9, 2022 · updated Mar 8, 2024

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
>= 3.2.0, < 3.2.23.2.2
>= 3.0.0, < 3.1.43.1.4
>= 2.0.0, < 2.10.12.10.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-269, CWE-863
Also known as
BIT-solr-2020-9492, CVE-2020-9492

More Apache Hadoop advisories

All Apache Hadoop
Advisory
Improper Authentication in Apache Hadoop
LowMay 17, 2022
Improper Authentication in Apache Hadoop
Medium6.5May 17, 2022
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
High7.5May 17, 2022
Insecure Inherited Permissions in Apache Hadoop
High8.8May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium5.5May 13, 2022
Path traversal in Hadoop
Critical9.8Apr 8, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.