CVE-2013-2193
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
29/05/2014
Last modified:
12/04/2025
Description
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:hbase:0.92.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.92.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.92.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:hbase:0.94.8:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/96615
- http://seclists.org/fulldisclosure/2013/Aug/250
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
- http://osvdb.org/96615
- http://seclists.org/fulldisclosure/2013/Aug/250
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html



