VYPR

Cdh

by Cloudera

CVEs (12)

  • CVE-2016-4572HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.01

    In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.

  • CVE-2015-7831HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.01

    In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.

  • CVE-2019-7319HigNov 26, 2019
    risk 0.54cvss 8.3epss 0.01

    An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser…

  • CVE-2016-5724HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.

  • CVE-2017-9325HigJul 3, 2019
    risk 0.49cvss 7.5epss 0.01

    The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.

  • CVE-2016-6605HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.01

    Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

  • CVE-2018-17860HigNov 26, 2019
    risk 0.47cvss 7.2epss 0.01

    Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.

  • CVE-2016-6353MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.

  • CVE-2016-3131MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

  • CVE-2014-0229MedMar 23, 2017
    risk 0.42cvss 6.5epss 0.02

    Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a…

  • CVE-2013-6446LowMar 23, 2017
    risk 0.20cvss 3.1epss 0.01

    The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.

  • CVE-2012-1574Apr 12, 2012
    risk 0.00cvss epss 0.05

    The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote…