Token Password Generation Vulnerability in Apache Hadoop
CVE-2012-4449
9.8CRITICAL
What is CVE-2012-4449?
Apache Hadoop prior to version 0.23.4, 1.x versions prior to 1.0.4, and 2.x versions prior to 2.0.2 have a vulnerability in generating token passwords using a 20-bit secret with Kerberos security features enabled. This weakness may expose token passwords to context-dependent attackers, allowing them to exploit the vulnerability through brute-force techniques to decipher secret keys.