Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Cloudera_manager
(Cloudera)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 22 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-11-08 | CVE-2021-29243 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. | Cloudera_manager | 6.1 | ||
2021-11-08 | CVE-2021-32482 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter. | Cloudera_manager | 6.1 | ||
2021-11-08 | CVE-2021-30132 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. | Cloudera_manager | 9.8 | ||
2021-11-08 | CVE-2021-32483 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard. | Cloudera_manager | 5.3 | ||
2019-06-20 | CVE-2018-15913 | An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The validity of this parameter was not checked. As a result, the user could be automatically redirected to an attacker's external site or perform a malicious JavaScript function that results in cross-site scripting (XSS). This was fixed by not allowing any value in the returnUrl... | Cloudera_manager | N/A | ||
2019-11-26 | CVE-2019-14449 | An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product. | Cloudera_manager | N/A | ||
2019-11-26 | CVE-2016-9271 | Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature. | Cloudera_manager | N/A | ||
2019-11-26 | CVE-2017-7399 | Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users. | Cloudera_manager | N/A | ||
2019-11-26 | CVE-2016-3192 | Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files. | Cloudera_manager | N/A | ||
2019-11-26 | CVE-2015-6495 | There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles. | Cloudera_manager | N/A |