CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles. | 7.5 |
High |
||
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs. | 7.5 |
High |
||
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs. | 3.1 |
Low |