Product:

Cloudera_manager

(Cloudera)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 22
Date Id Summary Products Score Patch Annotated
2021-11-08 CVE-2021-29243 Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. Cloudera_manager 6.1
2021-11-08 CVE-2021-32482 Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter. Cloudera_manager 6.1
2021-11-08 CVE-2021-30132 Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. Cloudera_manager 9.8
2021-11-08 CVE-2021-32483 Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard. Cloudera_manager 5.3
2019-06-20 CVE-2018-15913 An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The validity of this parameter was not checked. As a result, the user could be automatically redirected to an attacker's external site or perform a malicious JavaScript function that results in cross-site scripting (XSS). This was fixed by not allowing any value in the returnUrl... Cloudera_manager N/A
2019-11-26 CVE-2019-14449 An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product. Cloudera_manager N/A
2019-11-26 CVE-2016-9271 Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature. Cloudera_manager N/A
2019-11-26 CVE-2017-7399 Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users. Cloudera_manager N/A
2019-11-26 CVE-2016-3192 Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files. Cloudera_manager N/A
2019-11-26 CVE-2015-6495 There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles. Cloudera_manager N/A