Vulnerable Systems:
* Apache Software Foundation Hadoop 1.0.1
* Apache Software Foundation Hadoop 1.0
* Apache Software Foundation Hadoop 0.23.1
* Apache Software Foundation Hadoop 0.23
* Apache Software Foundation Hadoop 0.20.205 0
* Apache Software Foundation Hadoop 0.20.204 0
* Apache Software Foundation Hadoop 0.20.203 0
An attacker can exploit this issue to impersonate arbitrary users and perform unauthorized actions.
Apache Hadoop versions prior to 1.0.2 are vulnerable.
Vendor Status:
Apache Software Foundation as issued an update for this vulnerablity.