CVE-2014-0229

Description

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.37

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-0229 are fixed in Apache - hadoop-common 0.23.11Windows
Vulnerabilities CVE-2014-0229 are fixed in Apache - hadoop-common 2.4.1Windows
Vulnerabilities CVE-2014-0229 are fixed in Apache - hadoop-common for Linux 0.23.11Linux
Vulnerabilities CVE-2014-0229 are fixed in Apache - hadoop-common for Linux 2.4.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234