CVE-2013-2193: Medium severity Apache HBase vulnerability
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2193?
CVE-2013-2193 has a medium severity rating due to its potential to allow man-in-the-middle attacks.
How do I fix CVE-2013-2193?
To fix CVE-2013-2193, upgrade to Apache HBase version 0.92.3 or later for the 0.92.x branch or to version 0.94.9 or later for the 0.94.x branch.
What are the affected versions in CVE-2013-2193?
CVE-2013-2193 affects Apache HBase versions 0.92.0 through 0.92.2 and 0.94.0 through 0.94.8.
What impact does CVE-2013-2193 have on Kerberos authentication?
CVE-2013-2193 allows attackers to disable bidirectional authentication when Kerberos features are enabled.
What attacks can be performed using CVE-2013-2193?
An attacker can exploit CVE-2013-2193 to perform man-in-the-middle attacks, potentially leading to data exposure.