CVE-2013-6446
23.03.2017, 20:59
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.Enginsight
Vendor | Product | Version |
---|---|---|
cloudera | cdh | 4.0.0 |
cloudera | cdh | 4.0.1 |
cloudera | cdh | 4.1.0 |
cloudera | cdh | 4.1.1 |
cloudera | cdh | 4.1.2 |
cloudera | cdh | 4.1.3 |
cloudera | cdh | 4.1.4 |
cloudera | cdh | 4.1.5 |
cloudera | cdh | 4.2.0 |
cloudera | cdh | 4.2.1 |
cloudera | cdh | 4.2.2 |
cloudera | cdh | 4.3.0 |
cloudera | cdh | 4.3.1 |
cloudera | cdh | 4.3.2 |
cloudera | cdh | 4.4.0 |
cloudera | cdh | 4.5.0 |
cloudera | cdh | 5.0.0:beta |
𝑥
= Vulnerable software versions
Common Weakness Enumeration