Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r7g-325h-mxrm

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Improper Authentication in Apache Hadoop

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

Пакеты

Наименование

org.apache.hadoop:hadoop-common

maven
Затронутые версииВерсия исправления

>= 0.23.0, < 0.23.11

0.23.11

Наименование

org.apache.hadoop:hadoop-common

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.4.1

2.4.1

EPSS

Процентиль: 58%
0.0037
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
nvd
почти 9 лет назад

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

EPSS

Процентиль: 58%
0.0037
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287