Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hbase | Apache | 0.92.0 (including) | 0.92.0 (including) |
Hbase | Apache | 0.92.1 (including) | 0.92.1 (including) |
Hbase | Apache | 0.92.2 (including) | 0.92.2 (including) |
Hbase | Apache | 0.94.0 (including) | 0.94.0 (including) |
Hbase | Apache | 0.94.1 (including) | 0.94.1 (including) |
Hbase | Apache | 0.94.2 (including) | 0.94.2 (including) |
Hbase | Apache | 0.94.3 (including) | 0.94.3 (including) |
Hbase | Apache | 0.94.4 (including) | 0.94.4 (including) |
Hbase | Apache | 0.94.5 (including) | 0.94.5 (including) |
Hbase | Apache | 0.94.6 (including) | 0.94.6 (including) |
Hbase | Apache | 0.94.6.1 (including) | 0.94.6.1 (including) |
Hbase | Apache | 0.94.7 (including) | 0.94.7 (including) |
Hbase | Apache | 0.94.8 (including) | 0.94.8 (including) |