GHSA-pxv5-5vmp-3jj4

Suggest an improvement
Source
https://github.com/advisories/GHSA-pxv5-5vmp-3jj4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pxv5-5vmp-3jj4/GHSA-pxv5-5vmp-3jj4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pxv5-5vmp-3jj4
Aliases
  • CVE-2013-2192
Published
2022-05-17T02:54:07Z
Modified
2024-12-06T05:49:00.331067Z
Summary
Improper Authentication in Apache Hadoop
Details

The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.

Database specific
{
    "nvd_published_at": "2014-01-24T18:55:00Z",
    "cwe_ids": [
        "CWE-287"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2022-07-08T19:10:34Z"
}
References

Affected packages

Maven / org.apache.hadoop:hadoop-common

Package

Name
org.apache.hadoop:hadoop-common
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hadoop/hadoop-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.0.6-alpha

Affected versions

2.*

2.0.1-alpha
2.0.2-alpha
2.0.3-alpha
2.0.4-alpha
2.0.5-alpha

Database specific

{
    "last_known_affected_version_range": "<= 2.0.5-alpha"
}

Maven / org.apache.hadoop:hadoop-common

Package

Name
org.apache.hadoop:hadoop-common
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hadoop/hadoop-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.23.0
Fixed
0.23.9

Affected versions

0.*

0.23.1
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8