HIGH🇵🇱 Wersja polska

CVE-2017-15536

CVSS 8.8v3.0pub. 2018-02-05upd. 2024-11-21

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can exploit these vulnerabilities in combination to gain root access to CDSW nodes, gain access to the CDSW database which includes Kerberos keytabs of CDSW users and bcrypt hashed passwords, and gain access to other privileged information such as session tokens, invitation tokens, and environment variables.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Cloudera Data Science Workbench

    APP
    Cloudera
    1.0.0 – 1.2.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2018-11215CRITICAL9.8PL ✓same product

RCE w Cloudera Data Science Workbench 1.3.0 i wcześniejszych

CVE-2018-20091CRITICAL9.9PL ✓same product

SQL Injection w Cloudera Data Science Workbench — dostęp do bazy danych

CVE-2018-20090HIGH8.3same product

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can...

CVE-2018-15665MEDIUM5.3same product

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users c...

CVE-2021-30132CRITICAL9.8PL ✓same vendor

Nieprawidłowa kontrola dostępu w Cloudera Manager 7.2.4 — eskalacja uprawnień