Known Vulnerabilities for Cdh by Cloudera
Listed below are 10 of the newest known vulnerabilities associated with "Cdh" by "Cloudera".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-7319 json | An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend... | 8.3 - HIGH | 2019-11-26 | 2020-08-24 |
| CVE-2018-17860 json | Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1. | 7.2 - HIGH | 2019-11-26 | 2019-12-12 |
| CVE-2017-9325 json | The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs. | 7.5 - HIGH | 2019-07-03 | 2019-07-11 |
| CVE-2016-6605 json | Not Provided | 2017-04-10 | 2025-04-20 | |
| CVE-2016-6353 json | Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry... | 6.5 - MEDIUM | 2019-11-26 | 2019-12-12 |
| CVE-2016-5724 json | Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles. | 7.5 - HIGH | 2019-11-26 | 2019-12-10 |
| CVE-2016-4572 json | In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. | 8.8 - HIGH | 2019-11-26 | 2019-12-10 |
| CVE-2016-3131 json | Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. | 6.5 - MEDIUM | 2019-11-26 | 2019-12-10 |
| CVE-2015-7831 json | In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used. | 8.8 - HIGH | 2019-11-26 | 2019-12-12 |
| CVE-2014-0229 json | Not Provided | 2017-03-23 | 2025-04-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudera | Cdh | 6.1.0 | |||
| Application | Cloudera | Cdh | 6.0.1 | |||
| Application | Cloudera | Cdh | 6.0.0 | |||
| Application | Cloudera | Cdh | 5.9.3 | |||
| Application | Cloudera | Cdh | 5.9.2 | |||
| Application | Cloudera | Cdh | 5.9.1 | |||
| Application | Cloudera | Cdh | 5.9.0 | |||
| Application | Cloudera | Cdh | 5.8.5 | |||
| Application | Cloudera | Cdh | 5.8.4 | |||
| Application | Cloudera | Cdh | 5.8.3 | |||
| Application | Cloudera | Cdh | 5.8.2 | |||
| Application | Cloudera | Cdh | 5.8.0 | |||
| Application | Cloudera | Cdh | 5.7.2 | |||
| Application | Cloudera | Cdh | 5.7.1 | |||
| Application | Cloudera | Cdh | 5.7.0 | |||
| Application | Cloudera | Cdh | 5.6.1 | |||
| Application | Cloudera | Cdh | 5.6.0 | |||
| Application | Cloudera | Cdh | 5.5.6 | |||
| Application | Cloudera | Cdh | 5.5.5 | |||
| Application | Cloudera | Cdh | 5.5.4 |