Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cloudera manager vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-30132
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
Cloudera Cloudera Manager 7.2.4
8.8
CVSSv3
CVE-2017-7399
Cloudera Manager 5.8.x prior to 5.8.5, 5.9.x prior to 5.9.2, and 5.10.x prior to 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
Cloudera Cloudera Manager
Cloudera Cloudera Manager 5.10.0
8.1
CVSSv3
CVE-2018-11744
Cloudera Manager up to and including 5.15 has Incorrect Access Control.
Cloudera Cloudera Manager
7.5
CVSSv3
CVE-2015-6495
There is Sensitive Information in Cloudera Manager prior to 5.4.6 Diagnostic Support Bundles.
Cloudera Cloudera Manager
7.5
CVSSv3
CVE-2017-9326
The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager. The keystore file itself is not exposed.
Cloudera Cloudera Manager 5.11.0
7.5
CVSSv3
CVE-2016-4949
Cloudera Manager 5.5 and previous versions allows remote malicious users to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename parameter to /cmf/process/<process_id>/logs.
Cloudera Manager
7.5
CVSSv3
CVE-2016-4950
Cloudera Manager 5.5 and previous versions allows remote malicious users to enumerate user sessions via a request to /api/v11/users/sessions.
Cloudera Manager
6.5
CVSSv3
CVE-2016-3192
Cloudera Manager 5.x prior to 5.7.1 places Sensitive Data in cleartext Readable Files.
Cloudera Cloudera Manager
6.5
CVSSv3
CVE-2017-9327
Secret data of processes managed by CM is not secured by file permissions.
Cloudera Cloudera Manager 5.9.2
Cloudera Cloudera Manager 5.10.1
Cloudera Cloudera Manager 5.11.0
6.5
CVSSv3
CVE-2018-10815
An issue exists in Cloudera Manager prior to 5.13.4, 5.14.x prior to 5.14.4, and 5.15.x prior to 5.15.1. A read-only user can access sensitive cluster information.
Cloudera Cloudera Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »