CVE-2012-1574: Medium severity Apache Hadoop vulnerability
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1574?
CVE-2012-1574 has a moderate severity level due to its potential for unauthorized impersonation by authenticated users.
How do I fix CVE-2012-1574?
To fix CVE-2012-1574, upgrade Apache Hadoop to versions 1.0.2, 0.23.2, or higher.
What products are affected by CVE-2012-1574?
CVE-2012-1574 affects various versions of Apache Hadoop and Cloudera CDH, particularly versions from 0.20.203.0 to 0.23.1.
Who can exploit CVE-2012-1574?
CVE-2012-1574 can be exploited by remote authenticated users who have access to the affected Hadoop instances.
What are the potential impacts of CVE-2012-1574?
Exploitation of CVE-2012-1574 could lead to unauthorized access and impersonation, compromising the security of the Hadoop environment.