First published: Tue Nov 26 2019(Updated: )
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera CDH | >=5.0.0<5.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2016-6353.
The title of this vulnerability is 'Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.'
This vulnerability allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
Versions of Cloudera CDH between 5.0.0 and 5.7.0 are affected by this vulnerability.
The severity of this vulnerability is medium with a CVSS score of 6.5.
To fix this vulnerability, update your Cloudera CDH installation to version 5.7.0 or newer.