Cloudera
Cloudera CDH: vulnerabilidades y CVE
Cloudera CDH tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-7319 | Alta (8.3) | 1.0% | — | 26 nov 2019 | An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or… |
| CVE-2018-17860 | Alta (7.2) | 0.95% | — | 26 nov 2019 | Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1. |
| CVE-2016-6353 | Media (6.5) | 0.75% | — | 26 nov 2019 | Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler. |
| CVE-2016-5724 | Alta (7.5) | 1.2% | — | 26 nov 2019 | Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles. |
| CVE-2016-4572 | Alta (8.8) | 0.86% | — | 26 nov 2019 | In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. |
| CVE-2016-3131 | Media (6.5) | 0.67% | — | 26 nov 2019 | Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. |
| CVE-2015-7831 | Alta (8.8) | 1.1% | — | 26 nov 2019 | In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used. |
| CVE-2017-9325 | Alta (7.5) | 0.83% | — | 3 jul 2019 | The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs. |
| CVE-2016-6605 | Alta (7.5) | 1.4% | — | 10 abr 2017 | Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization. |
| CVE-2014-0229 | Media (6.5) | 1.6% | — | 23 mar 2017 | Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin… |
| CVE-2013-6446 | Baja (3.1) | 0.88% | — | 23 mar 2017 | The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging… |