First published: Thu Apr 12 2012(Updated: )
Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera Manager | =3.7.0 | |
Cloudera Manager | =3.7.0 | |
Cloudera Manager | =3.7.1 | |
Cloudera Manager | =3.7.1 | |
Cloudera Manager | =3.7.2 | |
Cloudera Manager | =3.7.2 | |
Cloudera Manager | =3.7.3 | |
Cloudera Manager | =3.7.3 | |
Cloudera Manager | =3.7.4 | |
Cloudera Manager | =3.7.4 | |
Cloudera Manager | =3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2230 is rated as a medium severity vulnerability due to its potential for user impersonation in Cloudera Manager.
You can fix CVE-2012-2230 by upgrading to Cloudera Manager version 3.7.5 or later.
CVE-2012-2230 affects Cloudera Manager versions 3.7.0 to 3.7.4 and Cloudera Service and Configuration Manager version 3.5.
No, exploitation of CVE-2012-2230 requires remote authenticated user access.
If Kerberos is enabled, the threat of CVE-2012-2230 is mitigated, as the vulnerability specifically arises when Kerberos is disabled.