Show filters
50 Total Results
Displaying 31-40 of 50
Sort by:
Attacker Value
Unknown

CVE-2018-10815

Disclosure Date: May 24, 2019 (last updated November 27, 2024)
An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information.
0
Attacker Value
Unknown

CVE-2018-20090

Disclosure Date: March 11, 2019 (last updated November 27, 2024)
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.
Attacker Value
Unknown

CVE-2018-17860

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
Attacker Value
Unknown

CVE-2015-8094

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
0
Attacker Value
Unknown

CVE-2017-15536

Disclosure Date: February 05, 2018 (last updated November 26, 2024)
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can exploit these vulnerabilities in combination to gain root access to CDSW nodes, gain access to the CDSW database which includes Kerberos keytabs of CDSW users and bcrypt hashed passwords, and gain access to other privileged information such as session tokens, invitation tokens, and environment variables.
0
Attacker Value
Unknown

CVE-2016-6605

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
0
Attacker Value
Unknown

CVE-2014-0229

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
0
Attacker Value
Unknown

CVE-2015-4078

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
0
Attacker Value
Unknown

CVE-2015-4166

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key.
0
Attacker Value
Unknown

CVE-2015-2263

Disclosure Date: March 23, 2017 (last updated November 26, 2024)
Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.
0