Vulnerabilities (CVE)

Filtered by vendor Cloudera Subscribe
Total 51 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22353 2 Cloudera, Ibm 3 Data Platform, Big Sql, Cloud Pak For Data 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480.
CVE-2021-29994 1 Cloudera 1 Hue 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cloudera Hue 4.6.0 allows XSS.
CVE-2021-32482 1 Cloudera 1 Cloudera Manager 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
CVE-2021-30132 1 Cloudera 1 Cloudera Manager 2023-12-10 7.5 HIGH 9.8 CRITICAL
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
CVE-2021-32483 1 Cloudera 1 Cloudera Manager 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
CVE-2021-29243 1 Cloudera 1 Cloudera Manager 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.
CVE-2021-32481 1 Cloudera 1 Hue 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Cloudera Hue 4.6.0 allows XSS via the type parameter.
CVE-2020-26936 1 Cloudera 1 Data Engineering 2023-12-10 6.8 MEDIUM 8.8 HIGH
Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.
CVE-2021-3167 1 Cloudera 1 Data Engineering 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
CVE-2016-9271 1 Cloudera 1 Cloudera Manager 2023-12-10 3.5 LOW 5.4 MEDIUM
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
CVE-2019-14449 1 Cloudera 1 Cloudera Manager 2023-12-10 3.5 LOW 5.4 MEDIUM
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.
CVE-2017-7399 1 Cloudera 1 Cloudera Manager 2023-12-10 6.5 MEDIUM 8.8 HIGH
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
CVE-2016-3192 1 Cloudera 1 Cloudera Manager 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
CVE-2018-20090 1 Cloudera 1 Data Science Workbench 2023-12-10 6.5 MEDIUM 8.3 HIGH
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.
CVE-2015-7831 1 Cloudera 1 Cdh 2023-12-10 6.5 MEDIUM 8.8 HIGH
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
CVE-2019-7319 1 Cloudera 1 Cdh 2023-12-10 6.5 MEDIUM 8.3 HIGH
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.
CVE-2018-17860 1 Cloudera 1 Cdh 2023-12-10 6.5 MEDIUM 7.2 HIGH
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
CVE-2016-5724 1 Cloudera 1 Cdh 2023-12-10 5.0 MEDIUM 7.5 HIGH
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
CVE-2016-3131 1 Cloudera 1 Cdh 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
CVE-2016-6353 1 Cloudera 1 Cdh 2023-12-10 3.5 LOW 6.5 MEDIUM
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.