Home/Product/cloudera cdh
Product

cloudera cdh

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-7319
all versions
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, Pam
8.3HIGH
CVE-2018-17860
>= 5.0.0 and <= 5.14.0
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
7.2HIGH
CVE-2016-6353
>= 5.0.0 and < 5.7.0
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry docu
6.5MEDIUM
CVE-2016-5724
< 5.9.0
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
7.5HIGH
CVE-2016-4572
all versions
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
8.8HIGH
CVE-2016-3131
>= 5.0.0 and < 5.3.10
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
6.5MEDIUM
CVE-2015-7831
>= 5.0.0 and < 5.4.9
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
8.8HIGH
CVE-2017-9325
<= 5.8.0
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
7.5HIGH
CVE-2016-6605
all versions
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
7.5HIGH
CVE-2014-0229
all versions
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization f
6.5MEDIUM
CVE-2013-6446
all versions
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication,
3.1LOW
CVE-2012-1574
all versions
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x befo
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin