Skip to content
Apache HadoopGHSA-pxv5-5vmp-3jj4

Improper Authentication in Apache Hadoop

LowCVE-2013-2192 · Published May 17, 2022 · updated Dec 6, 2024

The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
>= 2.0.0, < 2.0.6-alpha2.0.6-alpha
>= 0.23.0, < 0.23.90.23.9
Details and references

More Apache Hadoop advisories

All Apache Hadoop
Advisory
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium6.2May 17, 2022
Improper Access Control in Apache Hadoop
High8.8May 17, 2022
Improper Authentication in Apache Hadoop
Medium6.5May 17, 2022
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
High7.5May 17, 2022
Insecure Inherited Permissions in Apache Hadoop
High8.8May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium5.5May 13, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.