CVE-2018-11767: Apache Hadoop

High severity, CVSS 7.4. EPSS: 3.7% chance of exploitation in the next 30 days.

In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.

Affected products

  • Apache Hadoop: from 2.7.5, up to and including 2.7.6; from 2.8.3, up to and including 2.8.4; from 2.9.0, up to and including 2.9.1

Published 2019-03-21. Last modified 2026-06-17.