CVE-2013-6446

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
23/03/2017
Last modified:
20/04/2025

Description

The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudera:cdh:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:cloudera:cdh:4.4.0:*:*:*:*:*:*:*