CVE-2014-0229: Apache Hadoop

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

Affected products

  • Apache Hadoop: version 0.23.0 only; version 0.23.1 only; version 0.23.3 only; version 0.23.4 only; version 0.23.5 only; version 0.23.6 only; …
  • Cloudera Cdh: version 5.0.0 only

Published 2017-03-23. Last modified 2026-06-17.