PT-2014-2571 · Apache · Apache Hadoop

Published

2014-01-24

·

Updated

2022-05-17

·

CVE-2013-2192

CVSS v2.0

3.2

Low

VectorAV:A/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Hadoop versions 1.x prior to 1.2.1 Apache Hadoop versions 0.23.x prior to 0.23.9 Apache Hadoop versions 2.x prior to 2.0.6-alpha
Description The issue concerns the RPC protocol implementation in Apache Hadoop when Kerberos security features are enabled. It allows man-in-the-middle attackers to disable bidirectional authentication, forcing a downgrade to simple authentication and potentially obtaining sensitive information.
Recommendations For Apache Hadoop versions 1.x prior to 1.2.1, update to version 1.2.1 or later. For Apache Hadoop versions 0.23.x prior to 0.23.9, update to version 0.23.9 or later. For Apache Hadoop versions 2.x prior to 2.0.6-alpha, update to version 2.0.6-alpha or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2192
GHSA-PXV5-5VMP-3JJ4
RHSA-2014:0037

Affected Products

Apache Hadoop