CVE-2013-2193
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0015 (0.2%)
Percentile: 35.8%
EPSS: 2026-05-06
Affects
apache:hbaseTechnical description
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.
Published: 5/29/2014, 2:19:06 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://osvdb.org/96615
- http://seclists.org/fulldisclosure/2013/Aug/250
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
- http://osvdb.org/96615
- http://seclists.org/fulldisclosure/2013/Aug/250
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html