First published: Mon Oct 30 2017(Updated: )
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Hadoop | <=0.23.3 | |
Apache Hadoop | =1.0.0 | |
Apache Hadoop | =1.0.1 | |
Apache Hadoop | =1.0.2 | |
Apache Hadoop | =1.0.3 | |
Apache Hadoop | =2.0.0-alpha | |
Apache Hadoop | =2.0.1-alpha | |
Apache Hadoop | =2.0.2-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4449 is a vulnerability in Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 that allows context-dependent attackers to crack secret keys via a brute-force attack.
CVE-2012-4449 affects Apache Hadoop versions before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 when Kerberos security features are enabled.
The severity of CVE-2012-4449 is critical with a severity score of 9.8.
Context-dependent attackers can exploit CVE-2012-4449 by using a brute-force attack to crack secret keys.
To fix CVE-2012-4449, it is recommended to upgrade Apache Hadoop to version 0.23.4 or higher, 1.x to version 1.0.4 or higher, or 2.x to version 2.0.2 or higher.