← Back

CVE-2015-2263

nvd nist
Published: Mar 23, 2017Modified: May 13, 2026

JSON object

Loading...
3.3
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.

Affected (41)

1 product
Cloudera Manager
Configuration A
41 vulnerable
Vulnerable SoftwareAffected Versions
Cloudera
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.1.0
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1.4
Version 4.5.0
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.5.4
Version 4.6.0
Version 4.6.1
Version 4.6.2
Version 4.6.3
Version 4.7.0
Version 4.7.1
Version 4.7.2
Version 4.7.3
Version 5.0.0
Version 5.0.0 beta1
Version 5.0.0 beta2
Version 5.0.1
Version 5.0.2
Version 5.0.5
Version 5.1.0
Version 5.1.1
Version 5.1.2
Version 5.1.3
Version 5.1.4
Version 5.2.0
Version 5.2.1
Version 5.2.2
Version 5.2.4
Version 5.3.0
Version 5.3.1
Version 5.3.2

Related CWEs

Timeline

No history available yet.