Description
CVE-2020-9492 vuln. issue is found in 8x component maven:org.apache.hadoop:hadoop-hdfs-client (version3.2.0) It seems with the version 3.2.0 hdfs client might send authorization header to remote url without verification. (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9492)
Attachments
Issue Links
- is related to
-
SOLR-15942 Upgrade Hadoop to 3.3.1
- Closed
- links to