Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2018-20091 An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to ru… Data Science Workbench after 1.4.2 Fix from $2,3002019-06-07 MEDIUM 6.1 CVE-2018-5798 This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager. Cloudera Manager 5.12+ Fix from $1,6002019-06-07 MEDIUM 6.5 CVE-2018-10815 An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive clus… Cloudera Manager 5.13.4 / 5.14.4+ Fix from $1,6002019-05-24 MEDIUM 6.1 CVE-2015-8094 Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac… Hue 3.10.0+ Fix from $1,6002018-05-22 HIGH 8.8 CVE-2017-15536 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authentic… Data Science Workbench 1.2.0+ Fix from $1,9502018-02-05 HIGH 7.5 CVE-2016-6605 Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization. Cdh Mitigation only Fix from $1,9502017-04-10 CRITICAL 9.8 CVE-2015-4166 Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors relate… Key Trustee Server after 5.4.2 Fix from $2,3002017-03-23 HIGH 7.5 CVE-2016-4949 Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename… Manager after 5.5.0 Fix from $1,9502017-03-07 HIGH 7.5 CVE-2016-4950 Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions. Manager after 5.5.0 Fix from $1,9502017-03-07 MEDIUM 6.1 CVE-2016-4946 Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML v… Hue after 3.9.0 Fix from $1,6002017-03-07 MEDIUM 6.1 CVE-2016-4948 Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML… Manager after 5.5.0 Fix from $1,6002017-03-07 MEDIUM 5.3 CVE-2016-4947 Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete. Hue after 3.9.0 Fix from $1,6002017-03-07 MEDIUM 6.5 CVE-2012-2230 Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller… Cloudera Manager Mitigation only Fix from $1,6002012-04-12