Rewterz Threat Advisory – CVE-2021-23965 – Mozilla Firefox code execution
January 27, 2021Rewterz Threat Advisory – CVE-2021-3156 – Linux SUDO buffer overflow
January 27, 2021Rewterz Threat Advisory – CVE-2021-23965 – Mozilla Firefox code execution
January 27, 2021Rewterz Threat Advisory – CVE-2021-3156 – Linux SUDO buffer overflow
January 27, 2021Severity
High
Analysis Summary
CVE-2020-9492
Apache Hadoop could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper validation of SPNEGO authorization header. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges to trigger services to send server credentials to a webhdfs path for capturing the service principal.
Impact
Privilege escalation
Affected Vendors
Apache
Affected Products
- Apache Hadoop 2.0.0 alpha
- Apache Hadoop 3.0.0-alpha
- Apache Hadoop 2.10.0
- Apache Hadoop 3.1.3
Remediation
Upgrade to the latest version of Hadoop (3.3.0, 3.2.2, 3.1.4, 2.10.1 or later)