Show filters
50 Total Results
Displaying 31-40 of 50
Sort by:
Attacker Value
Unknown
CVE-2018-10815
Disclosure Date: May 24, 2019 (last updated November 27, 2024)
An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information.
0
Attacker Value
Unknown
CVE-2018-20090
Disclosure Date: March 11, 2019 (last updated November 27, 2024)
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.
0
Attacker Value
Unknown
CVE-2018-17860
Disclosure Date: November 12, 2018 (last updated November 27, 2024)
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
0
Attacker Value
Unknown
CVE-2015-8094
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
0
Attacker Value
Unknown
CVE-2017-15536
Disclosure Date: February 05, 2018 (last updated November 26, 2024)
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can exploit these vulnerabilities in combination to gain root access to CDSW nodes, gain access to the CDSW database which includes Kerberos keytabs of CDSW users and bcrypt hashed passwords, and gain access to other privileged information such as session tokens, invitation tokens, and environment variables.
0
Attacker Value
Unknown
CVE-2016-6605
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
0
Attacker Value
Unknown
CVE-2014-0229
Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
0
Attacker Value
Unknown
CVE-2015-4078
Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
0
Attacker Value
Unknown
CVE-2015-4166
Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key.
0
Attacker Value
Unknown
CVE-2015-2263
Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.
0