CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cloudera 1Data Science Workbench Nov 21, 2024 Nov 26, 2019 N/A· v4 8.3 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder. |
1Cloudera 1Data Science Workbench Nov 21, 2024 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors. |
1Cloudera 1Data Science Workbench Nov 21, 2024 Jun 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts. |
1Cloudera 1Data Science Workbench Nov 21, 2024 Jun 7, 2019 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database cont...Show more |
1Cloudera 1Data Science Workbench Nov 21, 2024 Feb 5, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can explo...Show more |