Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cloudera cloudera manager vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2021-30132
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
Cloudera Cloudera Manager 7.2.4
6.8
CVSSv2
CVE-2018-11744
Cloudera Manager up to and including 5.15 has Incorrect Access Control.
Cloudera Cloudera Manager
6.5
CVSSv2
CVE-2017-7399
Cloudera Manager 5.8.x prior to 5.8.5, 5.9.x prior to 5.9.2, and 5.10.x prior to 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
Cloudera Cloudera Manager
Cloudera Cloudera Manager 5.10.0
6.5
CVSSv2
CVE-2012-2230
Cloudera Manager 3.7.x prior to 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnera...
Cloudera Cloudera Manager 3.7.1
Cloudera Cloudera Manager 3.7.2
Cloudera Cloudera Manager 3.7.4
Cloudera Cloudera Manager 3.7.0
Cloudera Cloudera Manager 3.7.3
Cloudera Cloudera Service And Configuration Manager 3.5
5.5
CVSSv2
CVE-2018-6185
In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in addition to those in Apache Hadoop KMS: purge and undelete. The KMS...
Cloudera Cloudera Manager 5.12.1
Cloudera Cloudera Manager 5.13.0
Cloudera Navigator Key Trustee Kms 5.12.0
Cloudera Navigator Key Trustee Kms 5.13.0
Cloudera Cloudera Manager 5.13.1
Cloudera Cloudera Manager 5.12.0
Cloudera Cloudera Manager 5.12.2
5
CVSSv2
CVE-2021-32483
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
Cloudera Cloudera Manager 7.2.4
5
CVSSv2
CVE-2015-6495
There is Sensitive Information in Cloudera Manager prior to 5.4.6 Diagnostic Support Bundles.
Cloudera Cloudera Manager
5
CVSSv2
CVE-2016-4949
Cloudera Manager 5.5 and previous versions allows remote malicious users to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename parameter to /cmf/process/<process_id>/logs.
Cloudera Manager
5
CVSSv2
CVE-2016-4950
Cloudera Manager 5.5 and previous versions allows remote malicious users to enumerate user sessions via a request to /api/v11/users/sessions.
Cloudera Manager
4.3
CVSSv2
CVE-2021-29243
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.
Cloudera Cloudera Manager
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »