Aggregates CVE and security vulnerability intelligence across all cloudera-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk path handling and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-3884 | Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cloudera Hue. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Ace Editor web application. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose | [email protected] | 7.5 | 1.63% | 2025-05-21 | 2026-06-17 |
| CVE-2021-32483 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard. | [email protected] | 5.3 | 0.78% | 2021-11-08 | 2026-06-16 |
| CVE-2021-30132 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. | [email protected] | 9.8 | 1.08% | 2021-11-08 | 2026-06-16 |
| CVE-2021-32482 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter. | [email protected] | 6.1 | 0.57% | 2021-11-08 | 2026-06-16 |
| CVE-2021-32481 | Cloudera Hue 4.6.0 allows XSS via the type parameter. | [email protected] | 6.1 | 0.65% | 2021-11-08 | 2026-06-16 |
| CVE-2021-29994 | Cloudera Hue 4.6.0 allows XSS. | [email protected] | 6.1 | 0.87% | 2021-11-08 | 2026-06-16 |
| CVE-2021-29243 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. | [email protected] | 6.1 | 0.57% | 2021-11-08 | 2026-06-16 |
| CVE-2021-3167 | In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs. | [email protected] | 6.5 | 1.11% | 2021-03-15 | 2026-06-17 |
| CVE-2020-26936 | Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack. | [email protected] | 8.8 | 0.45% | 2020-11-26 | 2026-06-16 |
| CVE-2019-14449 | An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product. | [email protected] | 5.4 | 0.52% | 2019-11-26 | 2026-06-16 |
| CVE-2019-7319 | An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges. | [email protected] | 8.3 | 1.02% | 2019-11-26 | 2026-06-16 |
| CVE-2018-20090 | An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder. | [email protected] | 8.3 | 0.83% | 2019-11-26 | 2026-06-16 |
| CVE-2017-7399 | Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users. | [email protected] | 8.8 | 0.86% | 2019-11-26 | 2026-06-16 |
| CVE-2016-9271 | Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature. | [email protected] | 5.4 | 0.52% | 2019-11-26 | 2026-06-16 |
| CVE-2018-17860 | Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1. | [email protected] | 7.2 | 0.95% | 2019-11-26 | 2026-06-16 |
| CVE-2015-4457 | Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors. | [email protected] | 5.4 | 0.62% | 2019-11-26 | 2026-06-16 |
| CVE-2016-6353 | Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler. | [email protected] | 6.5 | 0.75% | 2019-11-26 | 2026-06-16 |
| CVE-2016-5724 | Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles. | [email protected] | 7.5 | 1.23% | 2019-11-26 | 2026-06-16 |
| CVE-2016-4572 | In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. | [email protected] | 8.8 | 0.86% | 2019-11-26 | 2026-06-16 |
| CVE-2016-3192 | Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files. | [email protected] | 6.5 | 0.61% | 2019-11-26 | 2026-06-16 |