CVE-2012-1574

UnknownEPSS 4.83%

Last modified

CVE-2012-1574 is a vulnerability of currently unknown severity. The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.. EPSS estimates a 4.83% chance of exploitation in the next 30 days.

Description

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.

Metrics

EPSS Probability
4.83%

90.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ApacheHadoop0.20.203.0
ApacheHadoop0.20.204.0
ApacheHadoop0.20.205.0
ApacheHadoop0.23.0
ApacheHadoop0.23.1
ApacheHadoop1.0.0
ApacheHadoop1.0.1
ClouderaCloudera Cdhcdh30
ClouderaHadoop0.20-sbin
ClouderaHadoop0.20.1\+169
ClouderaHadoop0.20.2\+923

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-1574?
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
How severe is CVE-2012-1574?
Severity scoring for CVE-2012-1574 is pending analysis. The EPSS model estimates a 4.83% probability of exploitation in the next 30 days.
How do I fix CVE-2012-1574?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-1574?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST