CVE-2016-4949: Infoleak
Published Mar 7, 2017
·Updated
Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename parameter to /cmf/process/<processid>/logs.
Affected Software
1 affected component
Cloudera Manager<=5.5.0
Event History
Mar 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4949?
CVE-2016-4949 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-4949?
To mitigate CVE-2016-4949, upgrade Cloudera Manager to version 5.6.0 or later.
3
What type of attack does CVE-2016-4949 allow?
CVE-2016-4949 enables remote attackers to access sensitive log information.
4
Which versions of Cloudera Manager are affected by CVE-2016-4949?
CVE-2016-4949 affects Cloudera Manager versions up to and including 5.5.0.
5
Is authentication required to exploit CVE-2016-4949?
CVE-2016-4949 can be exploited without authentication.