Date: Fri, 22 Jun 2018 06:07:45 -0700 From: Josh Elser <elserj@...che.org> To: dev <dev@...se.apache.org> Cc: user@...se.apache.org, oss-security@...ts.openwall.com Subject: CVE-2018-8025 on Apache HBase CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would be considered a different user or an unauthenticated user would be treated as an authenticated user. https://issues.apache.org/jira/browse/HBASE-20664 implements a fix for this issue, and this fix is contained in the following releases of Apache HBase: * 18.104.22.168 * 22.214.171.124 * 1.4.5 * 2.0.1 This vulnerability affects all 1.x and 2.x release lines (except 1.0.0). - The Apache HBase PMC
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ