CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:A/AC:H/Au:N/C:P/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
37.9%
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.
Vendor | Product | Version | CPE |
---|---|---|---|
apache | hadoop | 0.23.0 | cpe:2.3:a:apache:hadoop:0.23.0:*:*:*:*:*:*:* |
apache | hadoop | 0.23.1 | cpe:2.3:a:apache:hadoop:0.23.1:*:*:*:*:*:*:* |
apache | hadoop | 0.23.3 | cpe:2.3:a:apache:hadoop:0.23.3:*:*:*:*:*:*:* |
apache | hadoop | 0.23.4 | cpe:2.3:a:apache:hadoop:0.23.4:*:*:*:*:*:*:* |
apache | hadoop | 0.23.5 | cpe:2.3:a:apache:hadoop:0.23.5:*:*:*:*:*:*:* |
apache | hadoop | 0.23.6 | cpe:2.3:a:apache:hadoop:0.23.6:*:*:*:*:*:*:* |
apache | hadoop | 0.23.7 | cpe:2.3:a:apache:hadoop:0.23.7:*:*:*:*:*:*:* |
apache | hadoop | 0.23.8 | cpe:2.3:a:apache:hadoop:0.23.8:*:*:*:*:*:*:* |
apache | hadoop | 1.0.0 | cpe:2.3:a:apache:hadoop:1.0.0:*:*:*:*:*:*:* |
apache | hadoop | 1.0.1 | cpe:2.3:a:apache:hadoop:1.0.1:*:*:*:*:*:*:* |