Bugzilla – Bug 1134076
VUL-0: CVE-2018-11767: hadoop: Apache Hadoop KMS ACL regression
Last modified: 2019-05-15 12:43:40 UTC
rh#1696003 After the security fix for CVE-2017-15713, KMS has an access control regression, blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms such as LdapGroupsMapping, CompositeGroupsMapping, or NullGroupsMapping. References: https://seclists.org/oss-sec/2019/q1/173 References: https://bugzilla.redhat.com/show_bug.cgi?id=1696003 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11767 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11767
it does not look like it affects us, but please check
(In reply to Marcus Meissner from comment #1) > it does not look like it affects us, but please check Correct, we have version 0.18.1, which is not affected by the bug. We can close this one.
clsoing