PT-2014-2571 · Apache · Apache Hadoop
Published
2014-01-24
·
Updated
2022-05-17
·
CVE-2013-2192
CVSS v2.0
3.2
Low
| Vector | AV:A/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Hadoop versions 1.x prior to 1.2.1
Apache Hadoop versions 0.23.x prior to 0.23.9
Apache Hadoop versions 2.x prior to 2.0.6-alpha
Description
The issue concerns the RPC protocol implementation in Apache Hadoop when Kerberos security features are enabled. It allows man-in-the-middle attackers to disable bidirectional authentication, forcing a downgrade to simple authentication and potentially obtaining sensitive information.
Recommendations
For Apache Hadoop versions 1.x prior to 1.2.1, update to version 1.2.1 or later.
For Apache Hadoop versions 0.23.x prior to 0.23.9, update to version 0.23.9 or later.
For Apache Hadoop versions 2.x prior to 2.0.6-alpha, update to version 2.0.6-alpha or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Hadoop