OESA-2021-1201
Dashboard / Vulnerabilities / OESA-2021-1201
Summary: hadoop security update
Details: Apache Hadoop is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage. Security Fix(es): In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.(CVE-2020-9492)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1201, https://nvd.nist.gov/vuln/detail/CVE-2020-9492
Affected packages
Package
Name: hadoop
Purl: pkg:rpm/openEuler/hadoop&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
