Vulnerabilities > Cloudera > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-08 CVE-2021-32483 Unspecified vulnerability in Cloudera Manager 7.2.4
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
network
low complexity
cloudera
5.3
2021-11-08 CVE-2021-29243 Cross-site Scripting vulnerability in Cloudera Manager
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.
network
low complexity
cloudera CWE-79
6.1
2021-11-08 CVE-2021-29994 Cross-site Scripting vulnerability in Cloudera HUE 4.6.0
Cloudera Hue 4.6.0 allows XSS.
network
low complexity
cloudera CWE-79
6.1
2021-11-08 CVE-2021-32481 Cross-site Scripting vulnerability in Cloudera HUE 4.6.0
Cloudera Hue 4.6.0 allows XSS via the type parameter.
network
low complexity
cloudera CWE-79
6.1
2021-11-08 CVE-2021-32482 Cross-site Scripting vulnerability in Cloudera Manager
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
network
low complexity
cloudera CWE-79
6.1
2021-03-15 CVE-2021-3167 Information Exposure Through Log Files vulnerability in Cloudera Data Engineering 1.3.0
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
network
low complexity
cloudera CWE-532
6.5
2019-11-26 CVE-2019-14449 Cross-site Scripting vulnerability in Cloudera Manager
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1.
network
low complexity
cloudera CWE-79
5.4
2019-11-26 CVE-2016-9271 Cross-site Scripting vulnerability in Cloudera Manager
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
network
low complexity
cloudera CWE-79
5.4
2019-11-26 CVE-2015-4457 Cross-site Scripting vulnerability in Cloudera Manager
Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.
network
low complexity
cloudera CWE-79
5.4
2019-11-26 CVE-2016-6353 Incorrect Authorization vulnerability in Cloudera CDH
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
network
low complexity
cloudera CWE-863
6.5