CVE-2018-11768: Apache Hadoop

High severity, CVSS 7.5. EPSS: 6.6% chance of exploitation in the next 30 days.

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.

Affected products

  • Apache Hadoop: from 2.2.0, up to and including 2.8.4; from 2.9.0, up to and including 2.9.1; from 3.0.1, up to and including 3.0.3; from 3.1.0, up to and including 3.1.1; version 2.0.0 only; version 2.0.1 only; …

Published 2019-10-04. Last modified 2026-06-17.