First published: Tue Nov 26 2019(Updated: )
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera CDH | =5.5.0 | |
Cloudera CDH | =5.5.1 | |
Cloudera CDH | =5.5.2 | |
Cloudera CDH | =5.5.3 | |
Cloudera CDH | =5.5.4 | |
Cloudera CDH | =5.6.0 | |
Cloudera CDH | =5.6.1 | |
Cloudera CDH | =5.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2016-4572.
The severity of CVE-2016-4572 is high with a score of 8.8.
CVE-2016-4572 affects Cloudera CDH versions 5.5.0, 5.5.1, 5.5.2, 5.5.3, 5.5.4, 5.6.0, 5.6.1, and 5.7.0.
CVE-2016-4572 is a vulnerability in Cloudera CDH before 5.7.1 where Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
To fix CVE-2016-4572, upgrade to Cloudera CDH version 5.7.1 or later.