Apache Hadoop User Impersonation Vulnerability (2)

by Carol~ Moderator - 4/9/12 8:35 AM

In Reply to: VULNERABILITIES / FIXES - April 09, 2012 by Carol~ Moderator

Release Date : 2012-04-09

Criticality level : Less critical
Impact : Spoofing
Where : From remote
Solution Status : Unpatched

Software: Apache Hadoop 0.20.x

Description:
A vulnerability has been reported in Apache Hadoop, which can be exploited by malicious users to impersonate other users.

Solution:
Upgrade to version 1.0.2.

http://secunia.com/advisories/48775/