2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2015-2263" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2017-03-23T20:59:00.297" ,
"lastModified" : "2017-03-29T13:45:31.787" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process."
} ,
{
"lang" : "es" ,
"value" : "Cloudera Manager 4.x, 5.0.x en versiones anteriores a 5.0.6, 5.1.x en versiones anteriores a 5.1.5, 5.2.x en versiones anteriores a 5.2.5 y 5.3.x en versiones anteriores a 5.3.3 utiliza permisos globales de lectura para archivos en su directorio de configuraci\u00f3n al iniciar YARN NodeManager, permite a usuarios locales obtener informaci\u00f3n sensible leyendo los archivos, como demuestra yarn.keytab o ssl-server.xml en /var/run/cloudera-scm-agent/process."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 3.3 ,
"baseSeverity" : "LOW"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 1.4
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N" ,
"accessVector" : "LOCAL" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 2.1
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-264"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2B1DE30B-319C-42DA-9DCD-AAA1113EE7A3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C888621A-BAD7-4FB3-9948-F8B4DA889472"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FD101616-1911-4F6C-8144-C98F6CECEA94"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BBA62E61-1065-4617-BDBE-5DFD33862E21"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "44962AA9-2731-4177-8F01-7DE83FD685B3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5642BED-6B64-4993-A2E4-2ADDFB325367"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "72FA5F9F-1331-40F9-8D59-15D1CE769698"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB51A0E6-0C9E-4749-A85F-23D4DFC79DE9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FF9A52D-124B-4F6C-93B6-3FC58CFA5260"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.1.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "34337AD1-9081-4640-93CE-17B156CBB5E9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B01E3259-01C7-4418-828A-D4FEBC770956"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0D8D8CEB-5995-439F-9FF4-116BE47AE1AF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0E749571-EF56-4DB8-BD8E-6F56A25502BF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.5.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "052755F7-8132-413C-890A-BCA847D8F796"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.5.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5E4D17CB-695B-4C90-ACED-717C4CCBF8F6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D9C09608-631D-4AC9-98A9-BC256FC6691B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9917FD25-304A-4B0E-9C38-0743042B913B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.6.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1B5916AA-B658-4899-AB67-54104D1B2917"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.6.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD49F66E-072D-4697-828D-31EA8F39CC6C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "90131D83-6124-4F77-974B-7CE30DCA3177"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.7.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E85EC6B7-ACE0-4A80-9DAD-158F9796B575"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.7.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "26BD428C-84C5-45DD-ADB3-2180F718D155"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:4.7.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "61A06045-6DFD-4BCC-B89B-97BB6AF19363"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4EA001C9-4AC8-4107-8891-628BF99A702D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.0.0:beta1:*:*:*:*:*:*" ,
"matchCriteriaId" : "B1CB511F-1008-4765-876C-3E373F191D14"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.0.0:beta2:*:*:*:*:*:*" ,
"matchCriteriaId" : "F831A418-C9A0-4527-B2A9-5366F3042F32"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "64223B68-46CD-44B5-B6FC-27546FAFECB9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6C7C3769-2990-4D2B-A0D3-350FEB568291"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5EF367D3-5A51-4143-8E37-835B7D4050E8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A50ECD9B-00D2-4342-B264-6D37231031BE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5103CCF8-A0CC-4BB8-9269-6B061B7F3690"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "822A1CAB-EEEA-4F56-AAB8-5FF5285EF49C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F3733DFA-8D8E-4CC8-AD7C-DE6D81F4FCDD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.1.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "390A6A11-0947-4A24-87B1-A4D6A4BF59A0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FB05DE7-3A89-4BE6-B4BC-C7E609C7A0A2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4724F623-5ACC-4A3D-9E73-5E7397F79B28"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.2.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "843DF823-8EDD-49C5-8948-4EB067C5CF63"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.2.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3F65B171-68C2-43A7-B4F2-BAEC619922C0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "91B584EF-1E03-4D8E-986B-5DF9FB8F0E27"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "924D38B1-7622-4157-B855-A24563DE16BD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:cloudera:cloudera_manager:5.3.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6EDA954F-E608-448F-AE72-27158423ED19"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html#topic_1_0_3" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
}
]
}