{"id":"CVE-2013-2192","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-2192","summary":"Improper Authentication in Apache Hadoop","details":"The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.","published":"2022-05-17T02:54:07Z","modified":"2024-12-06T05:49:00.331067Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.hadoop:hadoop-common","fixedVersion":"2.0.6-alpha"},{"ecosystem":"Maven","name":"org.apache.hadoop:hadoop-common","fixedVersion":"0.23.9"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2192"},{"type":"WEB","url":"https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0037.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0400.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2013/Aug/251"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:49:00.331067Z"}}