Access Restriction Bypass Affecting org.apache.hadoop:hadoop-kms Open this link in a new tab package, versions [2.7.5, 2.7.7) [2.8.3, 2.8.5) [2.9.0, 2.9.2)

  • Attack Complexity


  • Confidentiality


Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id


  • published

    18 Mar 2019

  • disclosed

    18 Mar 2019

  • credit

    Wei-Chiu Chuang

How to fix?

Upgrade org.apache.hadoop:hadoop-kms to version 2.7.7, 2.8.5, 2.9.2 or higher.


org.apache.hadoop:hadoop-kms is a cryptographic key management server based on Hadoop’s KeyProvider API.

Affected versions of this package are vulnerable to Access Restriction Bypass. The KMS blocks users or grants access to users incorrectly, if the system uses non-default groups mapping mechanisms.