Vulnerabilities (CVE)

Filtered by vendor Cloudera Subscribe
Filtered by product Cdh
Total 11 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-7831 1 Cloudera 1 Cdh 2023-12-10 6.5 MEDIUM 8.8 HIGH
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
CVE-2019-7319 1 Cloudera 1 Cdh 2023-12-10 6.5 MEDIUM 8.3 HIGH
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.
CVE-2018-17860 1 Cloudera 1 Cdh 2023-12-10 6.5 MEDIUM 7.2 HIGH
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
CVE-2016-5724 1 Cloudera 1 Cdh 2023-12-10 5.0 MEDIUM 7.5 HIGH
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
CVE-2016-3131 1 Cloudera 1 Cdh 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
CVE-2016-6353 1 Cloudera 1 Cdh 2023-12-10 3.5 LOW 6.5 MEDIUM
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
CVE-2016-4572 1 Cloudera 1 Cdh 2023-12-10 6.5 MEDIUM 8.8 HIGH
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
CVE-2017-9325 1 Cloudera 1 Cdh 2023-12-10 6.4 MEDIUM 7.5 HIGH
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
CVE-2014-0229 2 Apache, Cloudera 2 Hadoop, Cdh 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.
CVE-2013-6446 1 Cloudera 1 Cdh 2023-12-10 3.5 LOW 3.1 LOW
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.
CVE-2016-6605 1 Cloudera 1 Cdh 2023-12-10 5.0 MEDIUM 7.5 HIGH
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.