Race condition in org.apache.hbase:hbase-thrift
High severity
GitHub Reviewed
Published
Oct 18, 2018
to the GitHub Advisory Database
•
Updated Mar 4, 2024
Package
Affected versions
= 2.0.0
>= 1.4.0, < 1.4.5
>= 1.3.0, <= 1.3.2.0
<= 1.2.6.0
Patched versions
2.0.1
1.4.5
1.3.2.1
1.2.6.1
Description
Published to the GitHub Advisory Database
Oct 18, 2018
Reviewed
Jun 16, 2020
Last updated
Mar 4, 2024
An issue in Apache HBase affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would be considered a different user or an unauthenticated user would be treated as an authenticated user. https://issues.apache.org/jira/browse/HBASE-20664 implements a fix for this issue. It has been fixed in versions: 1.2.6.1, 1.3.2.1, 1.4.5, 2.0.1.
References