CVE-2012-1574
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other…
Does this matter?
Lower severity and a low EPSS score (4.77%). Track it; it rarely justifies an emergency change on its own.
Description
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 4.77% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- apache/hadoop · cloudera/cloudera cdh · cloudera/hadoop
- Source
- secalert@redhat.com
References
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0051.html
- http://seclists.org/fulldisclosure/2012/Apr/70
- http://secunia.com/advisories/48775
- http://secunia.com/advisories/48776
- http://www.securityfocus.com/bid/52939
- https://ccp.cloudera.com/display/DOC/Cloudera+Security+BulletinVendor Advisory
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0051.html
- http://seclists.org/fulldisclosure/2012/Apr/70
- http://secunia.com/advisories/48775
- http://secunia.com/advisories/48776
- http://www.securityfocus.com/bid/52939
- https://ccp.cloudera.com/display/DOC/Cloudera+Security+BulletinVendor Advisory
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.