First published: Thu Mar 23 2017(Updated: )
Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera Key Trustee Server | <=5.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4166 has a severity rating that suggests potential for significant impact due to the possibility of losing encryption keys.
To fix CVE-2015-4166, upgrade Cloudera Key Trustee Server to version 5.4.3 or later.
CVE-2015-4166 may lead to the loss of an encryption key, resulting in potential loss of data confidentiality.
CVE-2015-4166 affects all versions of Cloudera Key Trustee Server prior to 5.4.3.
CVE-2015-4166 is considered a critical vulnerability due to its implications for data security and key management.