Vulnerabilities > Cloudera > Cloudera Manager > 5.0.1

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2015-2263 Permissions, Privileges, and Access Controls vulnerability in Cloudera Manager
Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.
local
low complexity
cloudera CWE-264
2.1