Rewterz
Rewterz Threat Advisory – CVE-2021-23965 – Mozilla Firefox code execution
January 27, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-3156 – Linux SUDO buffer overflow
January 27, 2021

Rewterz Threat Advisory – CVE-2020-9492 – Apache Hadoop privilege escalation

Severity

High

Analysis Summary

CVE-2020-9492

Apache Hadoop could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper validation of SPNEGO authorization header. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges to trigger services to send server credentials to a webhdfs path for capturing the service principal.

Impact

Privilege escalation

Affected Vendors

Apache

Affected Products

  • Apache Hadoop 2.0.0 alpha
  • Apache Hadoop 3.0.0-alpha
  • Apache Hadoop 2.10.0
  • Apache Hadoop 3.1.3

Remediation

Upgrade to the latest version of Hadoop (3.3.0, 3.2.2, 3.1.4, 2.10.1 or later)