CVE-2014-0229: Medium severity cloudera hadoop vulnerability
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0229?
CVE-2014-0229 is considered a high severity vulnerability due to its potential to allow unauthorized access to critical HDFS administrative commands.
How do I fix CVE-2014-0229?
To fix CVE-2014-0229, upgrade to Apache Hadoop version 0.23.11 or 2.4.1, or Cloudera CDH 5.0.2 or later, which includes the necessary authorization checks.
Who is affected by CVE-2014-0229?
CVE-2014-0229 affects Apache Hadoop versions 0.23.x prior to 0.23.11 and 2.x prior to 2.4.1, as well as Cloudera CDH 5.0.x before 5.0.2.
What kind of exploitation risks are associated with CVE-2014-0229?
Exploiting CVE-2014-0229 can lead to denial of service attacks or unauthorized management of HDFS, compromising data integrity and availability.
Is it safe to use older versions of Apache Hadoop in light of CVE-2014-0229?
Using older versions of Apache Hadoop that are vulnerable to CVE-2014-0229 poses significant security risks and is not recommended.