CVE-2019-0212

CVSS v3.0 7.5 (High)
75% Progress
CVSS v2.0 6 (Medium)
60% Progress
EPSS 0.24 % (62th)
0.24% Progress
Affected Products 1
Advisories 1

In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2019-03-28 22:29:00
(5 years ago)
Updated Date
2023-11-07 03:01:50
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Hbase from 2.0.0 version and 2.0.4 and prior versions cpe:2.3:a:apache:hbase >= 2.0.0 <= 2.0.4
  Apache Hbase from 2.1.0 version and 2.1.3 and prior versions cpe:2.3:a:apache:hbase >= 2.1.0 <= 2.1.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...