CVE-2013-2192
published 2014-01-24CVE-2013-2192: The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are…
PriorityP412low3.2CVSS 2.0
AVAACHAuNCPIPAN
EPSS
1.07%
61.3th percentile
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
| apache | hadoop | — | — |
CVSS provenance
nvdv2.03.2LOWAV:A/AC:H/Au:N/C:P/I:P/A:N
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Authentication in Apache Hadoop
osv·2022-05-17
CVE-2013-2192 [LOW] Improper Authentication in Apache Hadoop
Improper Authentication in Apache Hadoop
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.
GHSA
Improper Authentication in Apache Hadoop
ghsa·2022-05-17
CVE-2013-2192 [LOW] CWE-287 Improper Authentication in Apache Hadoop
Improper Authentication in Apache Hadoop
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.
Red Hat
hadoop: man-in-the-middle vulnerability
vendor_redhat·2013-08-23·CVSS 3.2
CVE-2013-2192 [LOW] hadoop: man-in-the-middle vulnerability
hadoop: man-in-the-middle vulnerability
The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.
Package: activemq (OpenShift Enterprise 1) - Not affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0037.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0400.htmlhttp://seclists.org/fulldisclosure/2013/Aug/251http://secunia.com/advisories/57915https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0037.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0400.htmlhttp://seclists.org/fulldisclosure/2013/Aug/251http://secunia.com/advisories/57915https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
2014-01-24
Published