PT-2017-5781 · Apache+1 · Apache Hadoop+1
Published
2017-03-23
·
Updated
2022-05-17
·
CVE-2014-0229
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache Hadoop versions 0.23.x through 0.23.10
Apache Hadoop versions 2.x through 2.4.0
Cloudera CDH versions 5.0.x through 5.0.1
Description:
The issue allows remote authenticated users to cause a denial of service or perform unnecessary operations by issuing certain HDFS admin commands, due to a lack of authorization checks for the
refreshNamenodes, deleteBlockPool, and shutdownDatanode commands.Recommendations:
For Apache Hadoop versions 0.23.x through 0.23.10, update to version 0.23.11 or later.
For Apache Hadoop versions 2.x through 2.4.0, update to version 2.4.1 or later.
For Cloudera CDH versions 5.0.x through 5.0.1, update to version 5.0.2 or later.
Fix
DoS
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Hadoop
Cloudera Cdh