Vulnerabilities > Cloudera > Data Science Workbench > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-07-03 CVE-2018-11215 OS Command Injection vulnerability in Cloudera Data Science Workbench
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.
network
low complexity
cloudera CWE-78
critical
9.8
2019-06-07 CVE-2018-20091 SQL Injection vulnerability in Cloudera Data Science Workbench 1.4.0/1.4.1/1.4.2
An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2.
network
low complexity
cloudera CWE-89
critical
9.9