{ "id": "CVE-2014-0229", "sourceIdentifier": "secalert@redhat.com", "published": "2017-03-23T20:59:00.203", "lastModified": "2017-03-28T18:03:31.947", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command." }, { "lang": "es", "value": "Apache Hadoop 0.23.x en versiones anteriores a 0.23.11 y 2.x en versiones anteriores a 2.4.1, como se utiliza en Cloudera CDH 5.0.x en versiones anteriores a 5.0.2, no verifica la autorizaci\u00f3n para los comandos de administraci\u00f3n HDFS (1) refreshNamenodes, (2) deleteBlockPool y (3) ShutdownDatanode, lo que permite a usuarios remotos autenticados provocar una denegaci\u00f3n de servicio (cierre de DataNodes) o realizar operaciones innecesarias emitiendo un comando." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-264" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cdh:5.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "BEFFAE88-DD05-4431-A011-385D48033BE1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cdh:5.0.0:beta:*:*:*:*:*:*", "matchCriteriaId": "B0293F82-7BA9-4608-96B7-CCED9A98313C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cdh:5.0.0:beta2:*:*:*:*:*:*", "matchCriteriaId": "BF18527D-BF9B-4495-AF89-F976322E3A69" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.0:*:*:*:*:*:*:*", "matchCriteriaId": "029481B4-F0BC-4C44-B5DB-4AE66AE92334" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.1:*:*:*:*:*:*:*", "matchCriteriaId": "501DBE03-139A-46E9-BFD5-B7D8245AD2C7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.3:*:*:*:*:*:*:*", "matchCriteriaId": "AD95328D-ED9A-4889-96E7-C7B3041745FB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.4:*:*:*:*:*:*:*", "matchCriteriaId": "65899B21-D364-4E6D-8E82-1D408BA4E2A6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.5:*:*:*:*:*:*:*", "matchCriteriaId": "5512B2DD-5136-4215-899C-FB48AFA8A2CC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.6:*:*:*:*:*:*:*", "matchCriteriaId": "68A3493C-3D69-46A9-920A-8BB44B090609" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.7:*:*:*:*:*:*:*", "matchCriteriaId": "74588026-F427-4E31-89FA-FFCE5B2EC108" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.8:*:*:*:*:*:*:*", "matchCriteriaId": "1FD4F0BA-614B-47A9-B916-DD1400FCE532" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.9:*:*:*:*:*:*:*", "matchCriteriaId": "3D8C1670-EFEF-409B-B985-5815B6791B24" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:0.23.10:*:*:*:*:*:*:*", "matchCriteriaId": "EF986316-0FB8-4AF9-B372-4FC53C957D8D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.0.0:alpha:*:*:*:*:*:*", "matchCriteriaId": "227941BD-D769-45AD-9D61-7FCA3C2264FA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.0.1:alpha:*:*:*:*:*:*", "matchCriteriaId": "18BF490A-0865-47C0-A143-0991B40BD259" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.0.2:alpha:*:*:*:*:*:*", "matchCriteriaId": "E091799F-203D-4C52-839E-E798770C0287" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.0.3:alpha:*:*:*:*:*:*", "matchCriteriaId": "80E53689-C56C-4104-B510-CB4116B898CB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.0.4:alpha:*:*:*:*:*:*", "matchCriteriaId": "591921C3-F7EA-402E-9C36-2EADF0417C72" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.0.5:alpha:*:*:*:*:*:*", "matchCriteriaId": "9FA774A9-81B3-4303-B254-C802B4DC8004" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.0.6:alpha:*:*:*:*:*:*", "matchCriteriaId": "877CAAE8-5E57-4D0D-A8EB-8CA696D0CE3F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.1.0:beta:*:*:*:*:*:*", "matchCriteriaId": "25DB127F-4293-4847-A8C4-C7F6B74762EE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.1.1:beta:*:*:*:*:*:*", "matchCriteriaId": "E8AE3E25-0726-4039-A3A8-B53F7CF0E638" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.2.0:*:*:*:*:*:*:*", "matchCriteriaId": "DC9B08F2-CF75-4875-BDE1-D5D9CC7BF7E8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.3.0:*:*:*:*:*:*:*", "matchCriteriaId": "11B47B33-C54B-47F7-8AB7-90A589EED6F9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:apache:hadoop:2.4.0:*:*:*:*:*:*:*", "matchCriteriaId": "377E3DCD-CEB7-400B-BD78-A4C1EE98E4E5" } ] } ] } ], "references": [ { "url": "https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html#concept_i1q_xvk_2r", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] } ] }