CVE-2016-4948: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a template; (2) KDC Server host, (3) Kerberos Security Realm, (4) Kerberos Encryption Types, (5) Advanced Configuration Snippet (Safety Valve) for [libdefaults] section of krb5.conf, (6) Advanced Configuration Snippet (Safety Valve) for the Default Realm in krb5.conf, (7) Advanced Configuration Snippet (Safety Valve) for remaining krb5.conf, or (8) Active Directory Account Prefix fields in the Kerberos wizard; or (9) classicWizard parameter to cmf/cloudera-director/redirect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4948?
CVE-2016-4948 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-4948?
To fix CVE-2016-4948, upgrade Cloudera Manager to version 5.5.1 or later to mitigate the XSS vulnerabilities.
What versions of Cloudera Manager are affected by CVE-2016-4948?
CVE-2016-4948 affects Cloudera Manager versions 5.5.0 and earlier.
What are the potential impacts of CVE-2016-4948?
The impact of CVE-2016-4948 includes the ability for remote attackers to inject arbitrary web scripts or HTML, leading to information disclosure or session hijacking.
Are there any workarounds for CVE-2016-4948?
There are no specific workarounds for CVE-2016-4948; the recommended approach is to upgrade to a patched version.