CVE-2012-3376
Client BlockTokens not checked in Apache Hadoop
EPSS 2.7%
描述
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
如何修補 CVE-2012-3376
要修補 CVE-2012-3376,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.hadoop:hadoop-client—升級至 2.0.1-alpha 或更新版本
CVE-2012-3376 正在被利用嗎?
低 — EPSS 為 2.7%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 2.0.0-alpha, < 2.0.1-alpha