CVE-2015-4078: Infoleak
Published Mar 23, 2017
·Updated
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
Affected Software
12 affected components
Cloudera Cloudera Manager=5.3.0
Cloudera Cloudera Manager=5.3.1
Cloudera Cloudera Manager=5.3.2
Cloudera Cloudera Manager=5.3.3
Cloudera Cloudera Manager=5.4.0
Cloudera Cloudera Manager=5.4.1
Cloudera Navigator=2.2.0
Cloudera Navigator=2.2.1
Cloudera Navigator=2.2.2
Cloudera Navigator=2.2.3
Cloudera Navigator=2.3.0
Cloudera Navigator=2.3.1
Event History
Mar 23, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4078?
CVE-2015-4078 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-4078?
To mitigate CVE-2015-4078, upgrade Cloudera Navigator to version 2.2.4 or 2.3.3 or later.
3
What types of attacks can exploit CVE-2015-4078?
CVE-2015-4078 can be exploited by man-in-the-middle attackers via a padding-oracle attack.
4
Which Cloudera Navigator versions are affected by CVE-2015-4078?
CVE-2015-4078 affects Cloudera Navigator versions 2.2.0 to 2.2.3 and 2.3.0 to 2.3.1.
5
What is the root cause of CVE-2015-4078?
CVE-2015-4078 is caused by the support for SSLv3 in Cloudera Navigator, which is vulnerable to the POODLE attack.