CVE-2012-3376
Client BlockTokens not checked in Apache Hadoop
EPSS 0.96%
Description
DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.
How to fix CVE-2012-3376
To remediate CVE-2012-3376, upgrade the affected package to a fixed version below.
- Maven/org.apache.hadoop:hadoop-client—upgrade to 2.0.1-alpha or later
Is CVE-2012-3376 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.0.0-alpha, < 2.0.1-alpha