CVE-2015-1776
- EPSS 0.07%
- Veröffentlicht 19.04.2016 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk when the Intermediate data encryption feature is enabled, which allows local users to obtain sensiti...
CVE-2015-7430
- EPSS 0.05%
- Veröffentlicht 02.01.2016 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecified vectors.
- EPSS 1.62%
- Veröffentlicht 05.12.2014 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public ta...
CVE-2013-2192
- EPSS 0.13%
- Veröffentlicht 24.01.2014 18:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtai...
CVE-2012-3376
- EPSS 1.3%
- Veröffentlicht 12.07.2012 19:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to b...
CVE-2012-1574
- EPSS 0.29%
- Veröffentlicht 12.04.2012 10:45:14
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other prod...