Known Vulnerabilities for products from Cloudera
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Cloudera".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-22353 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-03-14 | 2022-03-22 |
| CVE-2021-32483 json | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard. | 5.3 - MEDIUM | 2021-11-08 | 2022-07-12 |
| CVE-2021-32482 json | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter. | 6.1 - MEDIUM | 2021-11-08 | 2021-11-10 |
| CVE-2021-32481 json | Cloudera Hue 4.6.0 allows XSS via the type parameter. | 6.1 - MEDIUM | 2021-11-08 | 2021-11-09 |
| CVE-2021-30132 json | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. | 9.8 - CRITICAL | 2021-11-08 | 2022-07-12 |
| CVE-2021-29994 json | Cloudera Hue 4.6.0 allows XSS. | 6.1 - MEDIUM | 2021-11-08 | 2021-11-09 |
| CVE-2021-29243 json | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. | 6.1 - MEDIUM | 2021-11-08 | 2021-11-10 |
| CVE-2021-3167 json | In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server l... | 6.5 - MEDIUM | 2021-03-15 | 2022-06-28 |
| CVE-2020-26936 json | Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack. | 8.8 - HIGH | 2020-11-26 | 2020-12-01 |
| CVE-2019-14449 json | An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala q... | 5.4 - MEDIUM | 2019-11-26 | 2019-12-05 |
| CVE-2019-7319 json | An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend... | 8.3 - HIGH | 2019-11-26 | 2020-08-24 |
| CVE-2018-20091 json | An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any ... | 9.9 - CRITICAL | 2019-06-07 | 2019-06-10 |
| CVE-2018-20090 json | An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project... | 8.3 - HIGH | 2019-11-26 | 2019-12-12 |
| CVE-2018-17860 json | Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1. | 7.2 - HIGH | 2019-11-26 | 2019-12-12 |
| CVE-2018-15913 json | An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' param... | 6.1 - MEDIUM | 2019-06-20 | 2020-08-13 |
| CVE-2018-15665 json | An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list o... | 5.3 - MEDIUM | 2019-06-21 | 2019-06-21 |
| CVE-2018-11744 json | Cloudera Manager through 5.15 has Incorrect Access Control. | 8.1 - HIGH | 2019-07-11 | 2019-07-18 |
| CVE-2018-11215 json | Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack ... | 9.8 - CRITICAL | 2019-07-03 | 2020-08-24 |
| CVE-2018-10815 json | An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user c... | 6.5 - MEDIUM | 2019-05-24 | 2019-05-28 |
| CVE-2018-6185 json | In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete A... | 4.9 - MEDIUM | 2019-06-07 | 2019-06-11 |
Known software with vulnerabilities from Cloudera
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Cloudera | Cdh | 4.0.0 |
| Application | Cloudera | Cloudera Cdh | cdh3 |
| Application | Cloudera | Cloudera Manager | 3.7.0 |
| Application | Cloudera | Cloudera Service And Configuration Manager | 3.5 |
| Application | Cloudera | Data Engineering | 1.1 |
| Application | Cloudera | Data Science Workbench | 1.0.0 |
| Application | Cloudera | Hadoop | 0.20-sbin |
| Application | Cloudera | Hue | 3.10.0 |