GHSA-qmh2-h7r6-gm6q
Dashboard / Vulnerabilities / GHSA-qmh2-h7r6-gm6q
Summary: Client BlockTokens not checked in Apache Hadoop
Details: DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
References: https://nvd.nist.gov/vuln/detail/CVE-2012-3376, https://github.com/apache/hadoop, https://seclists.org/fulldisclosure/2012/Jul/78, https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html, http://archives.neohapsis.com/archives/bugtraq/2012-07/0049.html
Affected packages
Package
Name: org.apache.hadoop:hadoop-client
Purl: pkg:maven/org.apache.hadoop/hadoop-client
Affected ranges
Type: ECOSYSTEM
Events:
