7.4
CVSSv3

CVE-2018-11767

Published: 21/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache hadoop

Mailing Lists

CVE-2018-11767: Apache Hadoop KMS ACL regression Severity: Severe Vendor: The Apache Hadoop Software Foundation Versions affected: 290 to 291, 283 to 284, 275 to 276 Description: After the security fix for CVE-2017-15713, KMS has an access control regression, blocking users or granting access to users incorrectly, if the system use ...