CVE-2016-3131: Medium severity cloudera hadoop vulnerability
Published Nov 26, 2019
·Updated
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
Affected Software
4 affected components
Cloudera CDH>=5.0.0<5.3.10
Cloudera CDH>=5.4.0<5.4.10
Cloudera CDH>=5.5.0<5.5.4
Cloudera CDH=5.6.0
Event History
Nov 26, 2019
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
Description
Frequently Asked Questions
1
What is CVE-2016-3131?
CVE-2016-3131 is a vulnerability in Cloudera CDH before 5.6.1 that allows authorization bypass via direct internal API calls.
2
What software is affected by CVE-2016-3131?
Cloudera CDH versions between 5.0.0 and 5.3.10, between 5.4.0 and 5.4.10, between 5.5.0 and 5.5.4, and 5.6.0 are affected.
3
What is the severity of CVE-2016-3131?
CVE-2016-3131 has a severity rating of 6.5, which is considered medium.
4
How can I fix CVE-2016-3131?
To fix CVE-2016-3131, you should update your Cloudera CDH installation to version 5.6.1 or later.
5
Where can I find more information about CVE-2016-3131?
You can find more information about CVE-2016-3131 in the Cloudera CDH security bulletin: https://docs.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html#tsb_120