Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pxv5-5vmp-3jj4

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Authentication in Apache Hadoop

The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.

Пакеты

Наименование

org.apache.hadoop:hadoop-common

maven
Затронутые версииВерсия исправления

>= 2.0.0, <= 2.0.5-alpha

2.0.6-alpha

Наименование

org.apache.hadoop:hadoop-common

maven
Затронутые версииВерсия исправления

>= 0.23.0, < 0.23.9

0.23.9

EPSS

Процентиль: 32%
0.00125
Низкий

Дефекты

CWE-287

Связанные уязвимости

redhat
больше 12 лет назад

The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.

nvd
около 12 лет назад

The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.

EPSS

Процентиль: 32%
0.00125
Низкий

Дефекты

CWE-287