PT-2017-5781 · Apache+1 · Apache Hadoop+1
Publicado
2017-03-23
·
Atualizado
2022-05-17
·
CVE-2014-0229
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache Hadoop versions 0.23.x through 0.23.10
Apache Hadoop versions 2.x through 2.4.0
Cloudera CDH versions 5.0.x through 5.0.1
Description:
The issue allows remote authenticated users to cause a denial of service or perform unnecessary operations by issuing certain HDFS admin commands, due to a lack of authorization checks for the
refreshNamenodes, deleteBlockPool, and shutdownDatanode commands.Recommendations:
For Apache Hadoop versions 0.23.x through 0.23.10, update to version 0.23.11 or later.
For Apache Hadoop versions 2.x through 2.4.0, update to version 2.4.1 or later.
For Cloudera CDH versions 5.0.x through 5.0.1, update to version 5.0.2 or later.
Correção
DoS
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Hadoop
Cloudera Cdh