CVE-2017-7399: High severity Cloudera Cloudera Manager vulnerability
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-7399?
CVE-2017-7399 is a vulnerability in Cloudera Manager versions 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 that allows a read-only user to discover other users' usernames and elevate their privileges.
How severe is CVE-2017-7399?
CVE-2017-7399 has a severity score of 8.8 out of 10.
How does CVE-2017-7399 affect Cloudera Manager?
CVE-2017-7399 affects Cloudera Manager versions 5.8.x, 5.9.x, and 5.10.x.
How can I fix CVE-2017-7399?
To fix CVE-2017-7399, upgrade Cloudera Manager to version 5.8.5, 5.9.2, or 5.10.1.
Where can I find more information about CVE-2017-7399?
You can find more information about CVE-2017-7399 in Cloudera's Security Bulletin: https://docs.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html#concept_tvf_34r_1cb