Lucene search

K
cveRedhatCVE-2013-2192
HistoryJan 24, 2014 - 6:55 p.m.

CVE-2013-2192

2014-01-2418:55:04
CWE-287
redhat
web.nvd.nist.gov
41
cve-2013-2192
apache hadoop
rpc protocol
kerberos security
man-in-the-middle
authentication
nvd

CVSS2

3.2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:H/Au:N/C:P/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

37.9%

The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.

Affected configurations

Nvd
Node
apachehadoopMatch0.23.0
OR
apachehadoopMatch0.23.1
OR
apachehadoopMatch0.23.3
OR
apachehadoopMatch0.23.4
OR
apachehadoopMatch0.23.5
OR
apachehadoopMatch0.23.6
OR
apachehadoopMatch0.23.7
OR
apachehadoopMatch0.23.8
OR
apachehadoopMatch1.0.0
OR
apachehadoopMatch1.0.1
OR
apachehadoopMatch1.0.2
OR
apachehadoopMatch1.0.3
OR
apachehadoopMatch1.0.4
OR
apachehadoopMatch1.1.0
OR
apachehadoopMatch1.1.1
OR
apachehadoopMatch1.1.2
OR
apachehadoopMatch1.2.0
OR
apachehadoopMatch2.0.0alpha
OR
apachehadoopMatch2.0.1alpha
OR
apachehadoopMatch2.0.2alpha
OR
apachehadoopMatch2.0.3alpha
OR
apachehadoopMatch2.0.4alpha
OR
apachehadoopMatch2.0.5alpha
VendorProductVersionCPE
apachehadoop0.23.0cpe:2.3:a:apache:hadoop:0.23.0:*:*:*:*:*:*:*
apachehadoop0.23.1cpe:2.3:a:apache:hadoop:0.23.1:*:*:*:*:*:*:*
apachehadoop0.23.3cpe:2.3:a:apache:hadoop:0.23.3:*:*:*:*:*:*:*
apachehadoop0.23.4cpe:2.3:a:apache:hadoop:0.23.4:*:*:*:*:*:*:*
apachehadoop0.23.5cpe:2.3:a:apache:hadoop:0.23.5:*:*:*:*:*:*:*
apachehadoop0.23.6cpe:2.3:a:apache:hadoop:0.23.6:*:*:*:*:*:*:*
apachehadoop0.23.7cpe:2.3:a:apache:hadoop:0.23.7:*:*:*:*:*:*:*
apachehadoop0.23.8cpe:2.3:a:apache:hadoop:0.23.8:*:*:*:*:*:*:*
apachehadoop1.0.0cpe:2.3:a:apache:hadoop:1.0.0:*:*:*:*:*:*:*
apachehadoop1.0.1cpe:2.3:a:apache:hadoop:1.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 231

CVSS2

3.2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:H/Au:N/C:P/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

37.9%