CVE-2014-0229
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
Apache Hadoop 0.23.x en versiones anteriores a 0.23.11 y 2.x en versiones anteriores a 2.4.1, como se utiliza en Cloudera CDH 5.0.x en versiones anteriores a 5.0.2, no verifica la autorización para los comandos de administración HDFS (1) refreshNamenodes, (2) deleteBlockPool y (3) ShutdownDatanode, lo que permite a usuarios remotos autenticados provocar una denegación de servicio (cierre de DataNodes) o realizar operaciones innecesarias emitiendo un comando.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-03 CVE Reserved
- 2017-03-23 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudera Search vendor "Cloudera" | Cdh Search vendor "Cloudera" for product "Cdh" | 5.0.0 Search vendor "Cloudera" for product "Cdh" and version "5.0.0" | - |
Affected
| ||||||
Cloudera Search vendor "Cloudera" | Cdh Search vendor "Cloudera" for product "Cdh" | 5.0.0 Search vendor "Cloudera" for product "Cdh" and version "5.0.0" | beta |
Affected
| ||||||
Cloudera Search vendor "Cloudera" | Cdh Search vendor "Cloudera" for product "Cdh" | 5.0.0 Search vendor "Cloudera" for product "Cdh" and version "5.0.0" | beta2 |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.0 Search vendor "Apache" for product "Hadoop" and version "0.23.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.1 Search vendor "Apache" for product "Hadoop" and version "0.23.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.3 Search vendor "Apache" for product "Hadoop" and version "0.23.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.4 Search vendor "Apache" for product "Hadoop" and version "0.23.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.5 Search vendor "Apache" for product "Hadoop" and version "0.23.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.6 Search vendor "Apache" for product "Hadoop" and version "0.23.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.7 Search vendor "Apache" for product "Hadoop" and version "0.23.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.8 Search vendor "Apache" for product "Hadoop" and version "0.23.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.9 Search vendor "Apache" for product "Hadoop" and version "0.23.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 0.23.10 Search vendor "Apache" for product "Hadoop" and version "0.23.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.0 Search vendor "Apache" for product "Hadoop" and version "2.0.0" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.1 Search vendor "Apache" for product "Hadoop" and version "2.0.1" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.2 Search vendor "Apache" for product "Hadoop" and version "2.0.2" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.3 Search vendor "Apache" for product "Hadoop" and version "2.0.3" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.4 Search vendor "Apache" for product "Hadoop" and version "2.0.4" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.5 Search vendor "Apache" for product "Hadoop" and version "2.0.5" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.0.6 Search vendor "Apache" for product "Hadoop" and version "2.0.6" | alpha |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.1.0 Search vendor "Apache" for product "Hadoop" and version "2.1.0" | beta |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.1.1 Search vendor "Apache" for product "Hadoop" and version "2.1.1" | beta |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.2.0 Search vendor "Apache" for product "Hadoop" and version "2.2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.3.0 Search vendor "Apache" for product "Hadoop" and version "2.3.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hadoop Search vendor "Apache" for product "Hadoop" | 2.4.0 Search vendor "Apache" for product "Hadoop" and version "2.4.0" | - |
Affected
|