CVE-2012-4449: Critical severity Apache Hadoop vulnerability
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2012-4449?
CVE-2012-4449 is a vulnerability in Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 that allows context-dependent attackers to crack secret keys via a brute-force attack.
How does CVE-2012-4449 affect Apache Hadoop?
CVE-2012-4449 affects Apache Hadoop versions before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 when Kerberos security features are enabled.
What is the severity of CVE-2012-4449?
The severity of CVE-2012-4449 is critical with a severity score of 9.8.
How can context-dependent attackers exploit CVE-2012-4449?
Context-dependent attackers can exploit CVE-2012-4449 by using a brute-force attack to crack secret keys.
How can I fix CVE-2012-4449 in Apache Hadoop?
To fix CVE-2012-4449, it is recommended to upgrade Apache Hadoop to version 0.23.4 or higher, 1.x to version 1.0.4 or higher, or 2.x to version 2.0.2 or higher.