CVE-2013-6446: Low severity cloudera hadoop vulnerability
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6446?
CVE-2013-6446 has a medium severity rating due to its potential exposure of sensitive job information.
How do I fix CVE-2013-6446?
To fix CVE-2013-6446, upgrade Cloudera CDH to version 4.6.0 or later.
What systems are affected by CVE-2013-6446?
CVE-2013-6446 affects Cloudera CDH versions 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2.
What type of information is exposed in CVE-2013-6446?
CVE-2013-6446 allows remote authenticated users to access sensitive job information due to a failure to enforce job ACLs.
Is CVE-2013-6446 related to authentication issues?
Yes, CVE-2013-6446 is related to authentication issues in the JobHistory Server when using MRv2/YARN with HTTP authentication.