Home/Product/cloudera cdh
Product

cloudera cdh

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-7319
all versions
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, Pam
8.3HIGH
CVE-2018-17860
>= 5.0.0 and <= 5.14.0
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
7.2HIGH
CVE-2016-6353
>= 5.0.0 and < 5.7.0
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry docu
6.5MEDIUM
CVE-2016-5724
< 5.9.0
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
7.5HIGH
CVE-2016-4572
all versions
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
8.8HIGH
CVE-2016-3131
>= 5.0.0 and < 5.3.10
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
6.5MEDIUM
CVE-2015-7831
>= 5.0.0 and < 5.4.9
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
8.8HIGH
CVE-2017-9325
<= 5.8.0
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
7.5HIGH
CVE-2016-6605
all versions
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
7.5HIGH
CVE-2014-0229
all versions
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization f
6.5MEDIUM
CVE-2013-6446
all versions
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication,
3.1LOW
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin