← Back

CVE-2014-0229

nvd nist
Published: Mar 23, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

Affected (25)

Products: Cloudera: Cdh · Apache: Hadoop
1 product
Cdh
1 product
Hadoop
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cloudera
Version 5.0.0
Version 5.0.0 beta2
Version 5.0.0 beta
Configuration B
22 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 0.23.0
Version 0.23.10
Version 0.23.1
Version 0.23.3
Version 0.23.4
Version 0.23.5
Version 0.23.6
Version 0.23.7
Version 0.23.8
Version 0.23.9
Version 2.0.0 alpha
Version 2.0.1 alpha
Version 2.0.2 alpha
Version 2.0.3 alpha
Version 2.0.4 alpha
Version 2.0.5 alpha
Version 2.0.6 alpha
Version 2.1.0 beta
Version 2.1.1 beta
Version 2.2.0
Version 2.3.0
Version 2.4.0

Related CWEs

Timeline

No history available yet.