Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 22 Jun 2018 06:07:45 -0700
From: Josh Elser <>
To: dev <>
Subject: CVE-2018-8025 on Apache HBase

CVE-2018-8025 describes an issue in Apache HBase that affects the 
optional "Thrift 1" API server when running over HTTP. There is a 
race-condition which could lead to authenticated sessions being 
incorrectly applied to users, e.g. one authenticated user would be 
considered a different user or an unauthenticated user would be treated 
as an authenticated user. implements a fix for 
this issue, and this fix is contained in the following releases of 
Apache HBase:

* 1.4.5
* 2.0.1

This vulnerability affects all 1.x and 2.x release lines (except 1.0.0).

- The Apache HBase PMC

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ