Show filters
50 Total Results
Displaying 1-10 of 50
Sort by:
Attacker Value
Unknown

CVE-2021-30132

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
Attacker Value
Unknown

CVE-2021-32483

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
Attacker Value
Unknown

CVE-2021-32481

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Hue 4.6.0 allows XSS via the type parameter.
Attacker Value
Unknown

CVE-2021-29243

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.
Attacker Value
Unknown

CVE-2021-32482

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
Attacker Value
Unknown

CVE-2021-29994

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Hue 4.6.0 allows XSS.
Attacker Value
Unknown

CVE-2021-3167

Disclosure Date: March 15, 2021 (last updated February 22, 2025)
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
Attacker Value
Unknown

CVE-2020-26936

Disclosure Date: November 26, 2020 (last updated February 22, 2025)
Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.
Attacker Value
Unknown

CVE-2019-14449

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.
Attacker Value
Unknown

CVE-2019-7319

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.