CVE-2016-4572: High severity cloudera hadoop vulnerability
Published Nov 26, 2019
·Updated
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
Affected Software
8 affected components
Cloudera CDH=5.5.0
Cloudera CDH=5.5.1
Cloudera CDH=5.5.2
Cloudera CDH=5.5.3
Cloudera CDH=5.5.4
Cloudera CDH=5.6.0
Cloudera CDH=5.6.1
Cloudera CDH=5.7.0
Event History
Nov 26, 2019
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2016-4572.
2
What is the severity of CVE-2016-4572?
The severity of CVE-2016-4572 is high with a score of 8.8.
3
Which version of Cloudera CDH is affected by CVE-2016-4572?
CVE-2016-4572 affects Cloudera CDH versions 5.5.0, 5.5.1, 5.5.2, 5.5.3, 5.5.4, 5.6.0, 5.6.1, and 5.7.0.
4
What is the description of CVE-2016-4572?
CVE-2016-4572 is a vulnerability in Cloudera CDH before 5.7.1 where Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
5
How can I fix CVE-2016-4572?
To fix CVE-2016-4572, upgrade to Cloudera CDH version 5.7.1 or later.