CVE Vulnerabilities

CVE-2014-0229

Published: Mar 23, 2017 | Modified: Mar 28, 2017
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

Affected Software

Name Vendor Start Version End Version
Cdh Cloudera 5.0.0 (including) 5.0.0 (including)
Cdh Cloudera 5.0.0-beta (including) 5.0.0-beta (including)
Cdh Cloudera 5.0.0-beta2 (including) 5.0.0-beta2 (including)

References