Apache HadoopGHSA-9r7g-325h-mxrm
Improper Authentication in Apache Hadoop
Medium6.5CVE-2014-0229 · Published May 17, 2022 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hadoop:hadoop-common Maven | >= 0.23.0, < 0.23.11 | 0.23.11 |
| >= 2.0.0, < 2.4.1 | 2.4.1 |
Details and references
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2014-0229
More Apache Hadoop advisories
All Apache Hadoop| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation CVE-2017-7669High7.5fixed in 2.8.1, 3.0.0-alpha3 | High7.5 | 2.8.1, 3.0.0-alpha3 |
| May 172022 | Improper Authentication in Apache Hadoop CVE-2013-2192Lowfixed in 0.23.9, 2.0.6-alpha | Low | 0.23.9, 2.0.6-alpha |
| May 172022 | Improper Access Control in Apache Hadoop CVE-2016-5393High8.8fixed in 2.6.5, 2.7.3 | High8.8 | 2.6.5, 2.7.3 |
| May 172022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop CVE-2015-1776Medium6.2fixed in 2.6.5 | Medium6.2 | 2.6.5 |
| May 142022 | Insecure Inherited Permissions in Apache Hadoop CVE-2016-6811High8.8fixed in 2.7.4 | High8.8 | 2.7.4 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop CVE-2016-5001Medium5.5fixed in 2.6.4, 2.7.2 | Medium5.5 | 2.6.4, 2.7.2 |