cloudera CVE Vulnerabilities & CVE List (51)

Products (CPE): — CVEs: 51

cloudera vulnerability overview

Aggregates CVE and security vulnerability intelligence across all cloudera-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk path handling and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 120 of 51 CVEs
«« First « Prev Page 1 / 3 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-3884 Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cloudera Hue. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Ace Editor web application. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose [email protected] 7.5 1.63% 2025-05-21 2026-06-17
CVE-2021-32483 Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard. [email protected] 5.3 0.78% 2021-11-08 2026-06-16
CVE-2021-30132 Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. [email protected] 9.8 1.08% 2021-11-08 2026-06-16
CVE-2021-32482 Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter. [email protected] 6.1 0.57% 2021-11-08 2026-06-16
CVE-2021-32481 Cloudera Hue 4.6.0 allows XSS via the type parameter. [email protected] 6.1 0.65% 2021-11-08 2026-06-16
CVE-2021-29994 Cloudera Hue 4.6.0 allows XSS. [email protected] 6.1 0.87% 2021-11-08 2026-06-16
CVE-2021-29243 Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. [email protected] 6.1 0.57% 2021-11-08 2026-06-16
CVE-2021-3167 In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs. [email protected] 6.5 1.11% 2021-03-15 2026-06-17
CVE-2020-26936 Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack. [email protected] 8.8 0.45% 2020-11-26 2026-06-16
CVE-2019-14449 An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product. [email protected] 5.4 0.52% 2019-11-26 2026-06-16
CVE-2019-7319 An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges. [email protected] 8.3 1.02% 2019-11-26 2026-06-16
CVE-2018-20090 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder. [email protected] 8.3 0.83% 2019-11-26 2026-06-16
CVE-2017-7399 Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users. [email protected] 8.8 0.86% 2019-11-26 2026-06-16
CVE-2016-9271 Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature. [email protected] 5.4 0.52% 2019-11-26 2026-06-16
CVE-2018-17860 Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1. [email protected] 7.2 0.95% 2019-11-26 2026-06-16
CVE-2015-4457 Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors. [email protected] 5.4 0.62% 2019-11-26 2026-06-16
CVE-2016-6353 Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler. [email protected] 6.5 0.75% 2019-11-26 2026-06-16
CVE-2016-5724 Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles. [email protected] 7.5 1.23% 2019-11-26 2026-06-16
CVE-2016-4572 In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. [email protected] 8.8 0.86% 2019-11-26 2026-06-16
CVE-2016-3192 Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files. [email protected] 6.5 0.61% 2019-11-26 2026-06-16
«« First « Prev Page 1 / 3 Next »
cvelogic Threat Intelligence