Skip to content
Apache HadoopGHSA-9r7g-325h-mxrm

Improper Authentication in Apache Hadoop

Medium6.5CVE-2014-0229 · Published May 17, 2022 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
>= 0.23.0, < 0.23.110.23.11
>= 2.0.0, < 2.4.12.4.1
Details and references

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
CVE-2014-0229

More Apache Hadoop advisories

All Apache Hadoop
DateAdvisory
May 172022Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
CVE-2017-7669High7.5fixed in 2.8.1, 3.0.0-alpha3
May 172022Improper Authentication in Apache Hadoop
CVE-2013-2192Lowfixed in 0.23.9, 2.0.6-alpha
May 172022Improper Access Control in Apache Hadoop
CVE-2016-5393High8.8fixed in 2.6.5, 2.7.3
May 172022Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2015-1776Medium6.2fixed in 2.6.5
May 142022Insecure Inherited Permissions in Apache Hadoop
CVE-2016-6811High8.8fixed in 2.7.4
May 132022Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
CVE-2016-5001Medium5.5fixed in 2.6.4, 2.7.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.