First published: Tue Nov 26 2019(Updated: )
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera Cloudera Manager | >=5.0.0<=5.0.7 | |
Cloudera Cloudera Manager | >=5.1.0<=5.1.6 | |
Cloudera Cloudera Manager | >=5.3.0<=5.3.10 | |
Cloudera Cloudera Manager | >=5.4.0<=5.4.3 | |
Cloudera Cloudera Manager | >=5.4.5<=5.4.10 | |
Cloudera Cloudera Manager | >=5.5.0<=5.5.6 | |
Cloudera Cloudera Manager | >=5.6.0<=5.6.1 | |
Cloudera Cloudera Manager | >=5.7.0<=5.7.5 | |
Cloudera Cloudera Manager | >=5.8.0<=5.8.3 | |
Cloudera Cloudera Manager | >=5.9.0<=5.9.1 | |
Cloudera Cloudera Manager | =5.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7399 is a vulnerability in Cloudera Manager versions 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 that allows a read-only user to discover other users' usernames and elevate their privileges.
CVE-2017-7399 has a severity score of 8.8 out of 10.
CVE-2017-7399 affects Cloudera Manager versions 5.8.x, 5.9.x, and 5.10.x.
To fix CVE-2017-7399, upgrade Cloudera Manager to version 5.8.5, 5.9.2, or 5.10.1.
You can find more information about CVE-2017-7399 in Cloudera's Security Bulletin: https://docs.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html#concept_tvf_34r_1cb