PT-2017-5781 · Apache+1 · Apache Hadoop+1

Published

2017-03-23

·

Updated

2022-05-17

·

CVE-2014-0229

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Apache Hadoop versions 0.23.x through 0.23.10 Apache Hadoop versions 2.x through 2.4.0 Cloudera CDH versions 5.0.x through 5.0.1
Description: The issue allows remote authenticated users to cause a denial of service or perform unnecessary operations by issuing certain HDFS admin commands, due to a lack of authorization checks for the refreshNamenodes, deleteBlockPool, and shutdownDatanode commands.
Recommendations: For Apache Hadoop versions 0.23.x through 0.23.10, update to version 0.23.11 or later. For Apache Hadoop versions 2.x through 2.4.0, update to version 2.4.1 or later. For Cloudera CDH versions 5.0.x through 5.0.1, update to version 5.0.2 or later.

Fix

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0229
GHSA-9R7G-325H-MXRM

Affected Products

Apache Hadoop
Cloudera Cdh