HIGH🇬🇧 English

CVE-2017-15536

CVSS 8.8v3.0pub. 2018-02-05upd. 2024-11-21

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can exploit these vulnerabilities in combination to gain root access to CDSW nodes, gain access to the CDSW database which includes Kerberos keytabs of CDSW users and bcrypt hashed passwords, and gain access to other privileged information such as session tokens, invitation tokens, and environment variables.

oryginał EN
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Cloudera Data Science Workbench

    APP
    Cloudera
    1.0.0 – 1.2.0 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
LPE
CWE
Referencje

Powiązane podatności

CVE-2018-11215CRITICAL9.8PL ✓ten sam produkt

RCE w Cloudera Data Science Workbench 1.3.0 i wcześniejszych

CVE-2018-20091CRITICAL9.9PL ✓ten sam produkt

SQL Injection w Cloudera Data Science Workbench — dostęp do bazy danych

CVE-2018-20090HIGH8.3ten sam produkt

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can...

CVE-2018-15665MEDIUM5.3ten sam produkt

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users c...

CVE-2021-30132CRITICAL9.8PL ✓ten sam vendor

Nieprawidłowa kontrola dostępu w Cloudera Manager 7.2.4 — eskalacja uprawnień