Cloudera Manager 3.7.x prior to 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cloudera cloudera manager 3.7.1 |
||
cloudera cloudera manager 3.7.2 |
||
cloudera cloudera manager 3.7.4 |
||
cloudera cloudera manager 3.7.0 |
||
cloudera cloudera manager 3.7.3 |
||
cloudera cloudera service and configuration manager 3.5 |