CVE-2012-1574
medium
CVSS v3
—
CVSS v2
6.5
VIR risk
6.5
Description
Apache Hadoop allows impersonation of arbitrary cluster user accounts
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletin
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.hadoop:hadoop-main | >=0.23,<0.23.2 | 0.23.2 |
| Maven | org.apache.hadoop:hadoop-main | >=1.0,<1.0.2 | 1.0.2 |
References
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0051.html
- http://seclists.org/fulldisclosure/2012/Apr/70
- http://secunia.com/advisories/48775
- http://secunia.com/advisories/48776
- http://www.securityfocus.com/bid/52939
- https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletin
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
- https://nvd.nist.gov/vuln/detail/CVE-2012-1574
- https://github.com/apache/hadoop
- https://seclists.org/fulldisclosure/2012/Apr/70
- https://web.archive.org/web/20120720041621/https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletin#ClouderaSecurityBulletin-MapReducewithSecurity
- https://web.archive.org/web/20151001135054/http://archives.neohapsis.com/archives/bugtraq/2012-04/0051.html
- https://web.archive.org/web/20161215212154/https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html#topic_1_0_2
- https://web.archive.org/web/20200229125105/http://www.securityfocus.com/bid/52939
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.