CVE-2018-11744
- EPSS 0.39%
- Published 11.07.2019 14:15:10
- Last modified 21.11.2024 03:43:56
Cloudera Manager through 5.15 has Incorrect Access Control.
CVE-2017-9327
- EPSS 0.23%
- Published 03.07.2019 17:15:09
- Last modified 21.11.2024 03:35:50
Secret data of processes managed by CM is not secured by file permissions.
CVE-2017-9326
- EPSS 0.32%
- Published 03.07.2019 17:15:09
- Last modified 21.11.2024 03:35:50
The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager. The keystore file itself is not exposed.
CVE-2018-15913
- EPSS 0.31%
- Published 20.06.2019 19:15:09
- Last modified 21.11.2024 03:51:42
An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The validity of this parameter was ...
CVE-2018-6185
- EPSS 0.11%
- Published 07.06.2019 15:29:00
- Last modified 21.11.2024 04:10:14
In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in addition to those in Apache Hadoop KM...
CVE-2018-5798
- EPSS 0.26%
- Published 07.06.2019 15:29:00
- Last modified 21.11.2024 04:09:25
This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.
CVE-2018-10815
- EPSS 0.27%
- Published 24.05.2019 17:29:01
- Last modified 21.11.2024 03:42:04
An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information.
CVE-2015-4078
- EPSS 0.24%
- Published 23.03.2017 20:59:00
- Last modified 20.04.2025 01:37:25
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3...
CVE-2015-2263
- EPSS 0.04%
- Published 23.03.2017 20:59:00
- Last modified 20.04.2025 01:37:25
Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitiv...
CVE-2014-8733
- EPSS 0.06%
- Published 10.02.2015 19:59:00
- Last modified 12.04.2025 10:46:40
Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.