← Back

CVE-2012-4449

nvd nist
Published: Oct 30, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.

Affected (8)

Products: Apache: Hadoop
1 product
Hadoop
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Up to 0.23.3
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 2.0.0 alpha
Version 2.0.1 alpha
Version 2.0.2 alpha

Timeline

No history available yet.