9.8
CVSSv3

CVE-2012-4449

Published: 30/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Hadoop prior to 0.23.4, 1.x prior to 1.0.4, and 2.x prior to 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent malicious users to crack secret keys via a brute-force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

apache hadoop 1.0.3

apache hadoop 1.0.0

apache hadoop 2.0.0

apache hadoop 1.0.2

apache hadoop 1.0.1

apache hadoop 2.0.2

apache hadoop 2.0.1

apache hadoop