Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hue HIGH 7.5
CVE-2025-3884

Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…

Mitigation only
Fix from $1,950 2025-05-22
Cloudera Manager CRITICAL 9.8
CVE-2021-30132

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.

Mitigation only
Fix from $2,300 2021-11-08
Cloudera Manager MEDIUM 5.3
CVE-2021-32483

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.

Mitigation only
Fix from $1,600 2021-11-08
Cloudera Manager MEDIUM 6.1
CVE-2021-29243

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.

Fix: after 7.3.4
Fix from $1,600 2021-11-08
Hue MEDIUM 6.1
CVE-2021-29994

Cloudera Hue 4.6.0 allows XSS.

No fix yet
Fix from $1,600 2021-11-08
Hue MEDIUM 6.1
CVE-2021-32481

Cloudera Hue 4.6.0 allows XSS via the type parameter.

Mitigation only
Fix from $1,600 2021-11-08
Cloudera Manager MEDIUM 6.1
CVE-2021-32482

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.

Fix: after 7.3.4
Fix from $1,600 2021-11-08
Data Engineering MEDIUM 6.5
CVE-2021-3167

In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.

Mitigation only
Fix from $1,600 2021-03-15
Data Engineering HIGH 8.8
CVE-2020-26936

Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.

Fix: 1.1+
Fix from $1,950 2020-11-26
Cloudera Manager MEDIUM 5.4
CVE-2019-14449

An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cro…

Fix: 5.16.2+
Fix from $1,600 2019-11-26
Cdh HIGH 8.3
CVE-2019-7319

An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjan…

Mitigation only
Fix from $1,950 2019-11-26
Cloudera Manager HIGH 8.8
CVE-2017-7399

Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames …

Fix: after 5.9.1
Fix from $1,950 2019-11-26
Data Science Workbench HIGH 8.3
CVE-2018-20090

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and g…

Fix: after 1.4.2
Fix from $1,950 2019-11-26
Cloudera Manager MEDIUM 5.4
CVE-2016-9271

Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.

Fix: after 5.8.3
Fix from $1,600 2019-11-26
Cdh HIGH 7.2
CVE-2018-17860

Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.

Fix: after 5.14.0
Fix from $1,950 2019-11-26
Cloudera Manager MEDIUM 5.4
CVE-2015-4457

Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web …

Fix: 5.4.3+
Fix from $1,600 2019-11-26
Cdh HIGH 8.8
CVE-2015-7831

In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.

Fix: 5.4.9+
Fix from $1,950 2019-11-26
Cdh HIGH 8.8
CVE-2016-4572

In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.

Mitigation only
Fix from $1,950 2019-11-26
Cdh HIGH 7.5
CVE-2016-5724

Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.

Fix: 5.9.0+
Fix from $1,950 2019-11-26
Cdh MEDIUM 6.5
CVE-2016-3131

Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

Fix: 5.3.10 / 5.4.10+
Fix from $1,600 2019-11-26
Cloudera Manager MEDIUM 6.5
CVE-2016-3192

Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.

Fix: 5.5.4 / 5.6.1+
Fix from $1,600 2019-11-26
Cdh MEDIUM 6.5
CVE-2016-6353

Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security…

Fix: 5.7.0+
Fix from $1,600 2019-11-26
Cloudera Manager HIGH 7.5
CVE-2015-6495

There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.

Fix: 4.8.6 / 5.0.7+
Fix from $1,950 2019-11-26
Cloudera Manager HIGH 8.1
CVE-2018-11744

Cloudera Manager through 5.15 has Incorrect Access Control.

Fix: after 6.1.0
Fix from $1,950 2019-07-11
Cdh HIGH 7.5
CVE-2017-9325

The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.

Fix: after 5.11.1
Fix from $1,950 2019-07-03
Cloudera Manager HIGH 7.5
CVE-2017-9326

The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloud…

Mitigation only
Fix from $1,950 2019-07-03
Cloudera Manager MEDIUM 6.5
CVE-2017-9327

Secret data of processes managed by CM is not secured by file permissions.

No fix yet
Fix from $1,600 2019-07-03
Data Science Workbench CRITICAL 9.8
CVE-2018-11215

Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.

Fix: after 1.3.0
Fix from $2,300 2019-07-03
Data Science Workbench MEDIUM 5.3
CVE-2018-15665

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.

Fix: after 1.4.0
Fix from $1,600 2019-06-21
Cloudera Manager MEDIUM 6.1
CVE-2018-15913

An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the use…

Fix: after 5.15.0
Fix from $1,600 2019-06-20