CVE-2019-14449
Summary
| CVE | CVE-2019-14449 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 17:15:00 UTC |
| Updated | 2019-12-05 17:39:00 UTC |
| Description | An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudera | Cloudera Manager | All | All | All | All |
| Application | Cloudera | Cloudera Manager | 6.0.0 | All | All | All |
| Application | Cloudera | Cloudera Manager | 6.0.1 | All | All | All |
| Application | Cloudera | Cloudera Manager | 6.1.0 | All | All | All |
| Application | Cloudera | Cloudera Manager | All | All | All | All |
| Application | Cloudera | Cloudera Manager | 6.0.0 | All | All | All |
| Application | Cloudera | Cloudera Manager | 6.0.1 | All | All | All |
| Application | Cloudera | Cloudera Manager | 6.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cloudera Security Bulletins | 5.x | Cloudera Documentation | CONFIRM | docs.cloudera.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.