CVE-2012-1574
published 2012-04-12CVE-2012-1574: The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
4.83%
91.1th percentile
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| cloudera | cloudera_cdh | — | — |
| cloudera | cloudera_manager | — | — |
| cloudera | cloudera_manager | — | — |
| cloudera | cloudera_manager | — | — |
| cloudera | cloudera_manager | — | — |
| cloudera | cloudera_manager | — | — |
| cloudera | cloudera_service_and_configuration_manager | — | — |
| cloudera | hadoop | — | — |
| cloudera | hadoop | — | — |
| cloudera | hadoop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Hadoop allows impersonation of arbitrary cluster user accounts
osv·2022-05-17
CVE-2012-1574 [MEDIUM] Apache Hadoop allows impersonation of arbitrary cluster user accounts
Apache Hadoop allows impersonation of arbitrary cluster user accounts
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
GHSA
Apache Hadoop allows impersonation of arbitrary cluster user accounts
ghsa·2022-05-17
CVE-2012-1574 [MEDIUM] CWE-287 Apache Hadoop allows impersonation of arbitrary cluster user accounts
Apache Hadoop allows impersonation of arbitrary cluster user accounts
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.
GHSA
GHSA-53g2-fc94-rp68: Cloudera Manager 3
ghsa_unreviewed·2022-05-17·CVSS 6.5
CVE-2012-2230 [MEDIUM] GHSA-53g2-fc94-rp68: Cloudera Manager 3
Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2012-04/0051.htmlhttp://seclists.org/fulldisclosure/2012/Apr/70http://secunia.com/advisories/48775http://secunia.com/advisories/48776http://www.securityfocus.com/bid/52939https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletinhttps://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.htmlhttp://archives.neohapsis.com/archives/bugtraq/2012-04/0051.htmlhttp://seclists.org/fulldisclosure/2012/Apr/70http://secunia.com/advisories/48775http://secunia.com/advisories/48776http://www.securityfocus.com/bid/52939https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletinhttps://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
2012-04-12
Published