mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 17:21:36 +00:00
305 lines
12 KiB
JSON
305 lines
12 KiB
JSON
{
|
|
"id": "CVE-2015-2263",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2017-03-23T20:59:00.297",
|
|
"lastModified": "2017-03-29T13:45:31.787",
|
|
"vulnStatus": "Analyzed",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Cloudera Manager 4.x, 5.0.x en versiones anteriores a 5.0.6, 5.1.x en versiones anteriores a 5.1.5, 5.2.x en versiones anteriores a 5.2.5 y 5.3.x en versiones anteriores a 5.3.3 utiliza permisos globales de lectura para archivos en su directorio de configuraci\u00f3n al iniciar YARN NodeManager, permite a usuarios locales obtener informaci\u00f3n sensible leyendo los archivos, como demuestra yarn.keytab o ssl-server.xml en /var/run/cloudera-scm-agent/process."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV30": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.0",
|
|
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
|
|
"attackVector": "LOCAL",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "LOW",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 3.3,
|
|
"baseSeverity": "LOW"
|
|
},
|
|
"exploitabilityScore": 1.8,
|
|
"impactScore": 1.4
|
|
}
|
|
],
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
|
|
"accessVector": "LOCAL",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 2.1
|
|
},
|
|
"baseSeverity": "LOW",
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-264"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2B1DE30B-319C-42DA-9DCD-AAA1113EE7A3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C888621A-BAD7-4FB3-9948-F8B4DA889472"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "FD101616-1911-4F6C-8144-C98F6CECEA94"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BBA62E61-1065-4617-BDBE-5DFD33862E21"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.0.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "44962AA9-2731-4177-8F01-7DE83FD685B3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B5642BED-6B64-4993-A2E4-2ADDFB325367"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "72FA5F9F-1331-40F9-8D59-15D1CE769698"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CB51A0E6-0C9E-4749-A85F-23D4DFC79DE9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2FF9A52D-124B-4F6C-93B6-3FC58CFA5260"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.1.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "34337AD1-9081-4640-93CE-17B156CBB5E9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B01E3259-01C7-4418-828A-D4FEBC770956"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0D8D8CEB-5995-439F-9FF4-116BE47AE1AF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0E749571-EF56-4DB8-BD8E-6F56A25502BF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "052755F7-8132-413C-890A-BCA847D8F796"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.5.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5E4D17CB-695B-4C90-ACED-717C4CCBF8F6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D9C09608-631D-4AC9-98A9-BC256FC6691B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9917FD25-304A-4B0E-9C38-0743042B913B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1B5916AA-B658-4899-AB67-54104D1B2917"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.6.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CD49F66E-072D-4697-828D-31EA8F39CC6C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.7.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "90131D83-6124-4F77-974B-7CE30DCA3177"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.7.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E85EC6B7-ACE0-4A80-9DAD-158F9796B575"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.7.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "26BD428C-84C5-45DD-ADB3-2180F718D155"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:4.7.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "61A06045-6DFD-4BCC-B89B-97BB6AF19363"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.0.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4EA001C9-4AC8-4107-8891-628BF99A702D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.0.0:beta1:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B1CB511F-1008-4765-876C-3E373F191D14"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.0.0:beta2:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F831A418-C9A0-4527-B2A9-5366F3042F32"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.0.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "64223B68-46CD-44B5-B6FC-27546FAFECB9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.0.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6C7C3769-2990-4D2B-A0D3-350FEB568291"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.0.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5EF367D3-5A51-4143-8E37-835B7D4050E8"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A50ECD9B-00D2-4342-B264-6D37231031BE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5103CCF8-A0CC-4BB8-9269-6B061B7F3690"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.1.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "822A1CAB-EEEA-4F56-AAB8-5FF5285EF49C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.1.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F3733DFA-8D8E-4CC8-AD7C-DE6D81F4FCDD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.1.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "390A6A11-0947-4A24-87B1-A4D6A4BF59A0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2FB05DE7-3A89-4BE6-B4BC-C7E609C7A0A2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.2.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4724F623-5ACC-4A3D-9E73-5E7397F79B28"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.2.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "843DF823-8EDD-49C5-8948-4EB067C5CF63"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.2.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3F65B171-68C2-43A7-B4F2-BAEC619922C0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.3.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "91B584EF-1E03-4D8E-986B-5DF9FB8F0E27"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.3.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "924D38B1-7622-4157-B855-A24563DE16BD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:cloudera:cloudera_manager:5.3.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6EDA954F-E608-448F-AE72-27158423ED19"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html#topic_1_0_3",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |