{"id":"CVE-2018-8025","details":"CVE-2018-8025 describes an issue in Apache HBase that affects the optional \"Thrift 1\" API server when running over HTTP. There is a race-condition which could lead to authenticated sessions being incorrectly applied to users, e.g. one authenticated user would be considered a different user or an unauthenticated user would be treated as an authenticated user. https://issues.apache.org/jira/browse/HBASE-20664 implements a fix for this issue. It has been fixed in versions: 1.2.6.1, 1.3.2.1, 1.4.5, 2.0.1.","aliases":["GHSA-r86j-2gc6-2cq9"],"modified":"2026-07-08T11:34:56.684579Z","published":"2018-06-27T15:29:00.217Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/a919e38f587c714c386a01d40fc8f45bd4219a65aaf2dc0bb4eccc96%40%3Cdev.hbase.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/104554"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/hbase","events":[{"introduced":"0"},{"last_affected":"7483b111e4da77adbfc8062b3b22cbe7c2cb91c1"},{"introduced":"6ba4e7c94d455949c78c7b0d47672d004452d90f"},{"last_affected":"6ba4e7c94d455949c78c7b0d47672d004452d90f"}],"database_specific":{"cpe":["cpe:2.3:a:apache:hbase:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:hbase:0.92.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.0.0"},{"introduced":"0.92.0"},{"last_affected":"0.92.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["0.92.0","rel/2.0.0","2.0.0RC2","2.0.0RC1","2.0.0RC0","rel/2.0.0-beta-2","2.0.0-beta-2RC0.2","rel/2.0.0-beta-1","2.0.0-beta-1-RC1.7","2.0.0-beta-1-RC1.6","2.0.0-beta-1-RC1.5","2.0.0-beta-1-RC1.4","2.0.0-beta-1-RC1.3","2.0.0-beta-1-RC1.2","2.0.0-beta-1-RC1","2.0.0-beta-1-RC0","rel/2.0.0-alpha-3","2.0.0-alpha-3RC0.2","rel/2.0.0-alpha-2","2.0.0-alpha-2RC0","rel/2.0.0-alpha-1","2.0.0-alpha-1RC0","rel/0.92.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8025.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}