MEDIUM
Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API
Published Jun 10, 2014
4.0
MEDIUMCVSS 2.0
EPSS 1.85%
Description
Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API.
Affected products
No data.
OR
- ≤ 4.8.2
- 4.0.1
- 4.0.2
- 4.0.3
- 4.1
- 4.1.1
- 4.1.2
- 4.1.3
- 4.1.4
- 4.5.0
- 4.5.1
- 4.5.2
- 4.5.3
- 4.5.4
- 4.6.0
- 4.6.1
- 4.6.2
- 4.6.3
- 4.7.2
- 4.8.1
- 5.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://packetstormsecurity.com/files/126956/Cloudera-Manager-4.8.2-5.0.0-Information-Disclosure.html x_refsource_MISC
- http://www.cloudera.com/content/cloudera-content/cloudera-docs/SecurityBulletins/Security-Bulletin/csb_topic_2.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/archive/1/532312/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/67912 vdb-entryx_refsource_BID
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/126956/Cloudera-Manager-4.8.2-5.0.0-Information-Disclosure.html | x_refsource_MISC | |
| http://www.cloudera.com/content/cloudera-content/cloudera-docs/SecurityBulletins/Security-Bulletin/csb_topic_2.html | x_refsource_CONFIRMVendor Advisory | |
| http://www.securityfocus.com/archive/1/532312/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/67912 | vdb-entryx_refsource_BID |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 10, 2014
Updated Aug 6, 2024
Reserved Dec 3, 2013
Link CVE-2014-0220
CISA Vulnrichment
Updated n/a