Vulnerabilities > Cloudera > Cloudera Manager

DATE CVE VULNERABILITY TITLE RISK
2014-06-10 CVE-2014-0220 Information Exposure vulnerability in Cloudera Manager
Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API.
network
low complexity
cloudera CWE-200
4.0
2012-04-12 CVE-2012-2230 Cryptographic Issues vulnerability in Cloudera products
Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
network
low complexity
cloudera CWE-310
6.5