{ "id": "CVE-2014-0220", "sourceIdentifier": "secalert@redhat.com", "published": "2014-06-10T14:55:09.273", "lastModified": "2018-10-09T19:38:07.493", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API." }, { "lang": "es", "value": "Cloudera Manager anterior a 4.8.3 y 5.x anterior a 5.0.1 permite a usuarios remotos autenticados obtener informaci\u00f3n sensible de configuraciones a trav\u00e9s de la API." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-200" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:*:*:*:*:*:*:*:*", "versionEndIncluding": "4.8.2", "matchCriteriaId": "FBE1727C-81AC-4392-A65F-D5B134512EC0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "C888621A-BAD7-4FB3-9948-F8B4DA889472" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "FD101616-1911-4F6C-8144-C98F6CECEA94" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "BBA62E61-1065-4617-BDBE-5DFD33862E21" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1:*:*:*:*:*:*:*", "matchCriteriaId": "87F9F677-5B4B-4BF2-AC39-417C047C99B4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "72FA5F9F-1331-40F9-8D59-15D1CE769698" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "CB51A0E6-0C9E-4749-A85F-23D4DFC79DE9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "2FF9A52D-124B-4F6C-93B6-3FC58CFA5260" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "34337AD1-9081-4640-93CE-17B156CBB5E9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "B01E3259-01C7-4418-828A-D4FEBC770956" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "0D8D8CEB-5995-439F-9FF4-116BE47AE1AF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.2:*:*:*:*:*:*:*", "matchCriteriaId": "0E749571-EF56-4DB8-BD8E-6F56A25502BF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.3:*:*:*:*:*:*:*", "matchCriteriaId": "052755F7-8132-413C-890A-BCA847D8F796" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.4:*:*:*:*:*:*:*", "matchCriteriaId": "5E4D17CB-695B-4C90-ACED-717C4CCBF8F6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.0:*:*:*:*:*:*:*", "matchCriteriaId": "D9C09608-631D-4AC9-98A9-BC256FC6691B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "9917FD25-304A-4B0E-9C38-0743042B913B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.2:*:*:*:*:*:*:*", "matchCriteriaId": "1B5916AA-B658-4899-AB67-54104D1B2917" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.3:*:*:*:*:*:*:*", "matchCriteriaId": "CD49F66E-072D-4697-828D-31EA8F39CC6C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.7.2:*:*:*:*:*:*:*", "matchCriteriaId": "26BD428C-84C5-45DD-ADB3-2180F718D155" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.8.1:*:*:*:*:*:*:*", "matchCriteriaId": "EA2F9E44-F4EE-4E52-B455-49D6ECBF558D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "4EA001C9-4AC8-4107-8891-628BF99A702D" } ] } ] } ], "references": [ { "url": "http://packetstormsecurity.com/files/126956/Cloudera-Manager-4.8.2-5.0.0-Information-Disclosure.html", "source": "secalert@redhat.com" }, { "url": "http://www.cloudera.com/content/cloudera-content/cloudera-docs/SecurityBulletins/Security-Bulletin/csb_topic_2.html", "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/archive/1/532312/100/0/threaded", "source": "secalert@redhat.com" }, { "url": "http://www.securityfocus.com/bid/67912", "source": "secalert@redhat.com" } ] }