Apache HadoopGHSA-pxv5-5vmp-3jj4
Improper Authentication in Apache Hadoop
LowCVE-2013-2192 · Published May 17, 2022 · updated Dec 6, 2024
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hadoop:hadoop-common Maven | >= 2.0.0, < 2.0.6-alpha | 2.0.6-alpha |
| >= 0.23.0, < 0.23.9 | 0.23.9 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2013-2192
More Apache Hadoop advisories
All Apache Hadoop| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop | Medium6.2 | 2.6.5 |
| May 172022 | Improper Access Control in Apache Hadoop | High8.8 | 2.6.5+1 more |
| May 172022 | Improper Authentication in Apache Hadoop | Medium6.5 | 0.23.11+1 more |
| May 172022 | Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation | High7.5 | 2.8.1+1 more |
| May 142022 | Insecure Inherited Permissions in Apache Hadoop | High8.8 | 2.7.4 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop | Medium5.5 | 2.6.4+1 more |