mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-29 09:41:31 +00:00
234 lines
8.4 KiB
JSON
234 lines
8.4 KiB
JSON
![]() |
{
|
||
|
"id": "CVE-2014-0229",
|
||
|
"sourceIdentifier": "secalert@redhat.com",
|
||
|
"published": "2017-03-23T20:59:00.203",
|
||
|
"lastModified": "2017-03-28T18:03:31.947",
|
||
|
"vulnStatus": "Analyzed",
|
||
|
"descriptions": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command."
|
||
|
},
|
||
|
{
|
||
|
"lang": "es",
|
||
|
"value": "Apache Hadoop 0.23.x en versiones anteriores a 0.23.11 y 2.x en versiones anteriores a 2.4.1, como se utiliza en Cloudera CDH 5.0.x en versiones anteriores a 5.0.2, no verifica la autorizaci\u00f3n para los comandos de administraci\u00f3n HDFS (1) refreshNamenodes, (2) deleteBlockPool y (3) ShutdownDatanode, lo que permite a usuarios remotos autenticados provocar una denegaci\u00f3n de servicio (cierre de DataNodes) o realizar operaciones innecesarias emitiendo un comando."
|
||
|
}
|
||
|
],
|
||
|
"metrics": {
|
||
|
"cvssMetricV30": [
|
||
|
{
|
||
|
"source": "nvd@nist.gov",
|
||
|
"type": "Primary",
|
||
|
"cvssData": {
|
||
|
"version": "3.0",
|
||
|
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
|
||
|
"attackVector": "NETWORK",
|
||
|
"attackComplexity": "LOW",
|
||
|
"privilegesRequired": "LOW",
|
||
|
"userInteraction": "NONE",
|
||
|
"scope": "UNCHANGED",
|
||
|
"confidentialityImpact": "NONE",
|
||
|
"integrityImpact": "NONE",
|
||
|
"availabilityImpact": "HIGH",
|
||
|
"baseScore": 6.5,
|
||
|
"baseSeverity": "MEDIUM"
|
||
|
},
|
||
|
"exploitabilityScore": 2.8,
|
||
|
"impactScore": 3.6
|
||
|
}
|
||
|
],
|
||
|
"cvssMetricV2": [
|
||
|
{
|
||
|
"source": "nvd@nist.gov",
|
||
|
"type": "Primary",
|
||
|
"cvssData": {
|
||
|
"version": "2.0",
|
||
|
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
|
||
|
"accessVector": "NETWORK",
|
||
|
"accessComplexity": "LOW",
|
||
|
"authentication": "SINGLE",
|
||
|
"confidentialityImpact": "NONE",
|
||
|
"integrityImpact": "NONE",
|
||
|
"availabilityImpact": "PARTIAL",
|
||
|
"baseScore": 4.0
|
||
|
},
|
||
|
"baseSeverity": "MEDIUM",
|
||
|
"exploitabilityScore": 8.0,
|
||
|
"impactScore": 2.9,
|
||
|
"acInsufInfo": false,
|
||
|
"obtainAllPrivilege": false,
|
||
|
"obtainUserPrivilege": false,
|
||
|
"obtainOtherPrivilege": false,
|
||
|
"userInteractionRequired": false
|
||
|
}
|
||
|
]
|
||
|
},
|
||
|
"weaknesses": [
|
||
|
{
|
||
|
"source": "nvd@nist.gov",
|
||
|
"type": "Primary",
|
||
|
"description": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "CWE-264"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
],
|
||
|
"configurations": [
|
||
|
{
|
||
|
"nodes": [
|
||
|
{
|
||
|
"operator": "OR",
|
||
|
"negate": false,
|
||
|
"cpeMatch": [
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:cloudera:cdh:5.0.0:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "BEFFAE88-DD05-4431-A011-385D48033BE1"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:cloudera:cdh:5.0.0:beta:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "B0293F82-7BA9-4608-96B7-CCED9A98313C"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:cloudera:cdh:5.0.0:beta2:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "BF18527D-BF9B-4495-AF89-F976322E3A69"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"nodes": [
|
||
|
{
|
||
|
"operator": "OR",
|
||
|
"negate": false,
|
||
|
"cpeMatch": [
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.0:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "029481B4-F0BC-4C44-B5DB-4AE66AE92334"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.1:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "501DBE03-139A-46E9-BFD5-B7D8245AD2C7"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.3:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "AD95328D-ED9A-4889-96E7-C7B3041745FB"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.4:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "65899B21-D364-4E6D-8E82-1D408BA4E2A6"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.5:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "5512B2DD-5136-4215-899C-FB48AFA8A2CC"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.6:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "68A3493C-3D69-46A9-920A-8BB44B090609"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.7:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "74588026-F427-4E31-89FA-FFCE5B2EC108"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.8:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "1FD4F0BA-614B-47A9-B916-DD1400FCE532"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.9:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "3D8C1670-EFEF-409B-B985-5815B6791B24"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:0.23.10:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "EF986316-0FB8-4AF9-B372-4FC53C957D8D"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.0.0:alpha:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "227941BD-D769-45AD-9D61-7FCA3C2264FA"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.0.1:alpha:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "18BF490A-0865-47C0-A143-0991B40BD259"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.0.2:alpha:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "E091799F-203D-4C52-839E-E798770C0287"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.0.3:alpha:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "80E53689-C56C-4104-B510-CB4116B898CB"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.0.4:alpha:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "591921C3-F7EA-402E-9C36-2EADF0417C72"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.0.5:alpha:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "9FA774A9-81B3-4303-B254-C802B4DC8004"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.0.6:alpha:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "877CAAE8-5E57-4D0D-A8EB-8CA696D0CE3F"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.1.0:beta:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "25DB127F-4293-4847-A8C4-C7F6B74762EE"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.1.1:beta:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "E8AE3E25-0726-4039-A3A8-B53F7CF0E638"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.2.0:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "DC9B08F2-CF75-4875-BDE1-D5D9CC7BF7E8"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.3.0:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "11B47B33-C54B-47F7-8AB7-90A589EED6F9"
|
||
|
},
|
||
|
{
|
||
|
"vulnerable": true,
|
||
|
"criteria": "cpe:2.3:a:apache:hadoop:2.4.0:*:*:*:*:*:*:*",
|
||
|
"matchCriteriaId": "377E3DCD-CEB7-400B-BD78-A4C1EE98E4E5"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
],
|
||
|
"references": [
|
||
|
{
|
||
|
"url": "https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html#concept_i1q_xvk_2r",
|
||
|
"source": "secalert@redhat.com",
|
||
|
"tags": [
|
||
|
"Vendor Advisory"
|
||
|
]
|
||
|
}
|
||
|
]
|
||
|
}
|