CVE-2019-0212
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.
En todas las versiones anteriormente publicadas de Apache HBase 2.x (2.0.0-2.0.4, 2.1.0-2.1.3), se aplicaba una autorización de manera incorrecta a los usuarios del servidor REST "HBase". Todas las peticiones enviadas al servidor REST "HBase" se ejecutaban con los permisos del propio servidor REST y no con los permisos del usuario final. Este fallo solo es relevante cuando HBase está configurado con una autenticación Kerberos, la autorización HBase se encuentra habilitada y el servidor REST está configurado con una autenticación SPNEGO. Este fallo no va más allá del servidor REST "HBase".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-14 CVE Reserved
- 2019-03-28 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Hbase Search vendor "Apache" for product "Hbase" | >= 2.0.0 <= 2.0.4 Search vendor "Apache" for product "Hbase" and version " >= 2.0.0 <= 2.0.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hbase Search vendor "Apache" for product "Hbase" | >= 2.1.0 <= 2.1.3 Search vendor "Apache" for product "Hbase" and version " >= 2.1.0 <= 2.1.3" | - |
Affected
|