CVE-2017-7399

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
26/11/2019
Last modified:
04/12/2019

Description

Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.7 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.6 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.2.0 (including) 5.2.7 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.10 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.3 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.4.5 (including) 5.4.10 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.5.0 (including) 5.5.6 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.6.0 (including) 5.6.1 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.7.0 (including) 5.7.5 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.8.0 (including) 5.8.3 (including)
cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:* 5.9.0 (including) 5.9.1 (including)
cpe:2.3:a:cloudera:cloudera_manager:5.10.0:*:*:*:*:*:*:*