threat
engine
.sh
Back
·
··:··
Home
/
Product
/
cloudera cdh
Product
cloudera cdh
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2019-7319
all versions
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, Pam
8.3
HIGH
CVE-2018-17860
>= 5.0.0 and <= 5.14.0
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
7.2
HIGH
CVE-2016-6353
>= 5.0.0 and < 5.7.0
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry docu
6.5
MEDIUM
CVE-2016-5724
< 5.9.0
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
7.5
HIGH
CVE-2016-4572
all versions
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
8.8
HIGH
CVE-2016-3131
>= 5.0.0 and < 5.3.10
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
6.5
MEDIUM
CVE-2015-7831
>= 5.0.0 and < 5.4.9
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
8.8
HIGH
CVE-2017-9325
<= 5.8.0
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
7.5
HIGH
CVE-2016-6605
all versions
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
7.5
HIGH
CVE-2014-0229
all versions
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization f
6.5
MEDIUM
CVE-2013-6446
all versions
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication,
3.1
LOW
CVE-2012-1574
all versions
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x befo
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin