Cloudera
cloudera
51 CVEs • 13 products
Products (13)
Click to collapseToggle
Products (13)
Click to collapse
CVEs (51)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. |
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used. |
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles. |
Cloudera Manager through 5.15 has Incorrect Access Control. |
Secret data of processes managed by CM is not secured by file permissions. |
The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager. The keystore file itself is not exposed. |
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs. |
1Cloudera 1Data Science Workbench Nov 21, 2024 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors. |
1Cloudera 1Data Science Workbench Nov 21, 2024 Jun 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts. |
An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The v...Show more |
1Cloudera 1Data Science Workbench Nov 21, 2024 Jun 7, 2019 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database cont...Show more |
1Cloudera 2Cloudera Manager Navigator Key Trustee KmsNov 21, 2024 Jun 7, 2019 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in additio...Show more |
This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager. |
An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information. |
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter. |
1Cloudera 1Data Science Workbench Nov 21, 2024 Feb 5, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can explo...Show more |
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization. |
1Cloudera 1Key Trustee Server May 13, 2026 Mar 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key. |
1Cloudera 2Cloudera Manager NavigatorMay 13, 2026 Mar 23, 2017 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle a...Show more |
Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows...Show more |