9.8

CVE-2012-4449

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHadoop Version <= 0.23.3
ApacheHadoop Version1.0.0
ApacheHadoop Version1.0.1
ApacheHadoop Version1.0.2
ApacheHadoop Version1.0.3
ApacheHadoop Version2.0.0 Updatealpha
ApacheHadoop Version2.0.1 Updatealpha
ApacheHadoop Version2.0.2 Updatealpha
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.6
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.