Vulnerabilities > Cloudera > Low

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2013-6446 Permissions, Privileges, and Access Controls vulnerability in Cloudera CDH
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.
network
high complexity
cloudera CWE-264
3.1
2017-03-23 CVE-2015-2263 Permissions, Privileges, and Access Controls vulnerability in Cloudera Manager
Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.
local
low complexity
cloudera CWE-264
3.3
2017-03-23 CVE-2015-4078 Information Exposure vulnerability in Cloudera Manager and Navigator
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
network
high complexity
cloudera CWE-200
3.1