📦

cdh

Vendor: cloudera

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 59 Total Indexed
Avg. EPSS 0.30% Exploit Prob.
Latest CVE CVE-2019-7319 Nov 26

Security Vulnerability Index

Page 1 / 6
8.3 CVSS

An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.

EPSS: 0.59%
7.2 CVSS

Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.

EPSS: 0.27%
6.5 CVSS

Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.

EPSS: 0.17%
7.5 CVSS

Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.

EPSS: 0.40%
8.8 CVSS

In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.

EPSS: 0.33%
6.5 CVSS

Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

EPSS: 0.14%
8.8 CVSS

In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.

EPSS: 0.33%
7.5 CVSS

The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.

EPSS: 0.19%
7.5 CVSS

Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

EPSS: 0.21%
6.5 CVSS

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

EPSS: 0.46%