[MAVEN:GHSA-Q46V-CJ5V-HVG6] Use of a Broken or Risky Cryptographic Algorithm in Apache Hadoop

Severity Critical
Affected Packages 3
Fixed Packages 3
CVEs 1

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.

ID
MAVEN:GHSA-Q46V-CJ5V-HVG6
Severity
critical
URL
https://github.com/advisories/GHSA-q46v-cj5v-hvg6
Published
2022-05-17T00:22:31
(2 years ago)
Modified
2023-01-27T05:02:34
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.hadoop/hadoop-client org.apache.hadoop hadoop-client >= 2.0.0 < 2.0.2
Fixed pkg:maven/org.apache.hadoop/hadoop-client org.apache.hadoop hadoop-client = 2.0.2
Affected pkg:maven/org.apache.hadoop/hadoop-client org.apache.hadoop hadoop-client >= 1.0.0 < 1.0.4
Fixed pkg:maven/org.apache.hadoop/hadoop-client org.apache.hadoop hadoop-client = 1.0.4
Affected pkg:maven/org.apache.hadoop/hadoop-client org.apache.hadoop hadoop-client < 0.23.4
Fixed pkg:maven/org.apache.hadoop/hadoop-client org.apache.hadoop hadoop-client = 0.23.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...