Race Condition Vulnerability in Apache HBase's Thrift API Server
CVE-2018-8025

8.1HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
27 June 2018

Summary

A vulnerability exists in Apache HBase's optional Thrift 1 API server when accessed over HTTP, exposing a race condition that impacts session management. This flaw may cause authenticated sessions to be improperly assigned, allowing one user to impersonate another or an unauthenticated user to gain access as an authenticated user. It is essential for users of HBase to upgrade to the fixed versions to mitigate this security risk.

Affected Version(s)

Apache HBase Apache Tomcat 1.x and 2.x, excluding 1.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.