Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
BID:61984
Info
Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
| Bugtraq ID: | 61984 |
| Class: | Design Error |
| CVE: |
CVE-2013-2192 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2013 12:00AM |
| Updated: | Apr 22 2014 03:18AM |
| Credit: | Kyle Leckie of Microsoft and Aaron T.Myers of Cloudera |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
Apache Hadoop is prone to a security-bypass vulnerability.
Attackers can exploit this issue through man-in-the-middle attacks to gain access to sensitive information.
The following versions are affected:
Hadoop 2.0 through 2.0.6
Hadoop 0.23 through 0.23.9
Hadoop 1.0 through 1.2.1
Apache Hadoop is prone to a security-bypass vulnerability.
Attackers can exploit this issue through man-in-the-middle attacks to gain access to sensitive information.
The following versions are affected:
Hadoop 2.0 through 2.0.6
Hadoop 0.23 through 0.23.9
Hadoop 1.0 through 1.2.1
Exploit / POC
Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
An attacker may use readily available tools to exploit this issue.
An attacker may use readily available tools to exploit this issue.
Solution / Fix
Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Hadoop RPC Authentication CVE-2013-2192 Man in the Middle Security Bypass Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)