6.5

CVE-2014-0229

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cloudera ≫ Cdh Version 5.0.0
Cloudera ≫ Cdh Version 5.0.0 Update beta
Cloudera ≫ Cdh Version 5.0.0 Update beta2
Apache ≫ Hadoop Version 0.23.0
Apache ≫ Hadoop Version 0.23.1
Apache ≫ Hadoop Version 0.23.3
Apache ≫ Hadoop Version 0.23.4
Apache ≫ Hadoop Version 0.23.5
Apache ≫ Hadoop Version 0.23.6
Apache ≫ Hadoop Version 0.23.7
Apache ≫ Hadoop Version 0.23.8
Apache ≫ Hadoop Version 0.23.9
Apache ≫ Hadoop Version 0.23.10
Apache ≫ Hadoop Version 2.0.0 Update alpha
Apache ≫ Hadoop Version 2.0.1 Update alpha
Apache ≫ Hadoop Version 2.0.2 Update alpha
Apache ≫ Hadoop Version 2.0.3 Update alpha
Apache ≫ Hadoop Version 2.0.4 Update alpha
Apache ≫ Hadoop Version 2.0.5 Update alpha
Apache ≫ Hadoop Version 2.0.6 Update alpha
Apache ≫ Hadoop Version 2.1.0 Update beta
Apache ≫ Hadoop Version 2.1.1 Update beta
Apache ≫ Hadoop Version 2.2.0
Apache ≫ Hadoop Version 2.3.0
Apache ≫ Hadoop Version 2.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.59% 0.725
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html#concept_i1q_xvk_2r
Vendor Advisory