-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The CVE-2014-0229 description explicitly identifies three HDFS admin commands (refreshNamenodes, deleteBlockPool, shutdownDatanode) that lacked authorization checks. These commands map directly to method handlers in the DataNode class, which would be invoked when the commands are executed. The vulnerability manifests in these functions because they process critical operations without performing necessary authentication validation. In runtime profiling, these methods would appear in stack traces when attackers exploit the missing authorization checks to trigger datanode operations.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.hadoop:hadoop-common | maven | >= 0.23.0, < 0.23.11 | 0.23.11 |
| org.apache.hadoop:hadoop-common | maven | >= 2.0.0, < 2.4.1 | 2.4.1 |
Ongoing coverage of React2Shell