CVE-2012-3376
published 2012-07-12CVE-2012-3376: DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.63%
83.9th percentile
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Client BlockTokens not checked in Apache Hadoop
ghsa·2022-05-17
CVE-2012-3376 [HIGH] Client BlockTokens not checked in Apache Hadoop
Client BlockTokens not checked in Apache Hadoop
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
OSV
Client BlockTokens not checked in Apache Hadoop
osv·2022-05-17
CVE-2012-3376 [HIGH] Client BlockTokens not checked in Apache Hadoop
Client BlockTokens not checked in Apache Hadoop
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2012-07/0049.htmlhttp://www.securityfocus.com/bid/54358https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.htmlhttp://archives.neohapsis.com/archives/bugtraq/2012-07/0049.htmlhttp://www.securityfocus.com/bid/54358https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
2012-07-12
Published