{"id":"GHSA-pxv5-5vmp-3jj4","summary":"Improper Authentication in Apache Hadoop","details":"The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.","aliases":["CVE-2013-2192"],"modified":"2024-12-06T05:49:00.331067Z","published":"2022-05-17T02:54:07Z","database_specific":{"cwe_ids":["CWE-287"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2022-07-08T19:10:34Z","nvd_published_at":"2014-01-24T18:55:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2192"},{"type":"WEB","url":"https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0037.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0400.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2013/Aug/251"}],"affected":[{"package":{"name":"org.apache.hadoop:hadoop-common","ecosystem":"Maven","purl":"pkg:maven/org.apache.hadoop/hadoop-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.6-alpha"}]}],"versions":["2.0.1-alpha","2.0.2-alpha","2.0.3-alpha","2.0.4-alpha","2.0.5-alpha"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.5-alpha","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pxv5-5vmp-3jj4/GHSA-pxv5-5vmp-3jj4.json"}},{"package":{"name":"org.apache.hadoop:hadoop-common","ecosystem":"Maven","purl":"pkg:maven/org.apache.hadoop/hadoop-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.23.0"},{"fixed":"0.23.9"}]}],"versions":["0.23.1","0.23.3","0.23.4","0.23.5","0.23.6","0.23.7","0.23.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pxv5-5vmp-3jj4/GHSA-pxv5-5vmp-3jj4.json"}}],"schema_version":"1.9.0"}