Описание
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
Ссылки
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:apache:hadoop:2.0.0:alpha:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01302
Низкий
7.5 High
CVSS2
Дефекты
CWE-310
Связанные уязвимости
debian
больше 13 лет назад
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens ...
EPSS
Процентиль: 79%
0.01302
Низкий
7.5 High
CVSS2
Дефекты
CWE-310