CVE-2020-9492
ADVISORY - githubSummary
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
EPSS Score: 0.00143 (0.346)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Incorrect Authorization
ADVISORY - gitlab
ADVISORY - redhat
Incorrect Authorization
NIST
CREATED
UPDATED
ADVISORY IDCVE-2020-9492
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.8highGitHub
CVSS SCORE
8.8highBitnami
CREATED
UPDATED
ADVISORY ID
BIT-2020-9492
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighBitnami
CREATED
UPDATED
ADVISORY ID
BIT-solr-2020-9492
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
8.8highRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2020-9492
EXPLOITABILITY SCORE
2.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)