Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Science Workbench CRITICAL 9.9
CVE-2018-20091

An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to ru…

Fix: after 1.4.2
Fix from $2,300 2019-06-07
Cloudera Manager MEDIUM 6.1
CVE-2018-5798

This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.

Fix: 5.12+
Fix from $1,600 2019-06-07
Cloudera Manager MEDIUM 6.5
CVE-2018-10815

An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive clus…

Fix: 5.13.4 / 5.14.4+
Fix from $1,600 2019-05-24
Hue MEDIUM 6.1
CVE-2015-8094

Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…

Fix: 3.10.0+
Fix from $1,600 2018-05-22
Data Science Workbench HIGH 8.8
CVE-2017-15536

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authentic…

Fix: 1.2.0+
Fix from $1,950 2018-02-05
Cdh HIGH 7.5
CVE-2016-6605

Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

Mitigation only
Fix from $1,950 2017-04-10
Key Trustee Server CRITICAL 9.8
CVE-2015-4166

Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors relate…

Fix: after 5.4.2
Fix from $2,300 2017-03-23
Manager HIGH 7.5
CVE-2016-4949

Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename…

Fix: after 5.5.0
Fix from $1,950 2017-03-07
Manager HIGH 7.5
CVE-2016-4950

Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions.

Fix: after 5.5.0
Fix from $1,950 2017-03-07
Hue MEDIUM 6.1
CVE-2016-4946

Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML v…

Fix: after 3.9.0
Fix from $1,600 2017-03-07
Manager MEDIUM 6.1
CVE-2016-4948

Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML…

Fix: after 5.5.0
Fix from $1,600 2017-03-07
Hue MEDIUM 5.3
CVE-2016-4947

Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.

Fix: after 3.9.0
Fix from $1,600 2017-03-07
Cloudera Manager MEDIUM 6.5
CVE-2012-2230

Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller…

Mitigation only
Fix from $1,600 2012-04-12