First published: Tue Nov 26 2019(Updated: )
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera CDH | >=5.0.0<5.3.10 | |
Cloudera CDH | >=5.4.0<5.4.10 | |
Cloudera CDH | >=5.5.0<5.5.4 | |
Cloudera CDH | =5.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3131 is a vulnerability in Cloudera CDH before 5.6.1 that allows authorization bypass via direct internal API calls.
Cloudera CDH versions between 5.0.0 and 5.3.10, between 5.4.0 and 5.4.10, between 5.5.0 and 5.5.4, and 5.6.0 are affected.
CVE-2016-3131 has a severity rating of 6.5, which is considered medium.
To fix CVE-2016-3131, you should update your Cloudera CDH installation to version 5.6.1 or later.
You can find more information about CVE-2016-3131 in the Cloudera CDH security bulletin: https://docs.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html#tsb_120