CVE-2017-9325: High severity Cloudera CDH vulnerability
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-9325?
CVE-2017-9325 is a vulnerability that affects Cloudera CDH versions 5.8.0 to 5.11.1 and allows unauthorized access to the /update/json/docs endpoint.
How does CVE-2017-9325 impact Cloudera CDH?
CVE-2017-9325 allows attackers to bypass Sentry authorization and gain unauthorized access to the /update/json/docs endpoint.
What is the severity level of CVE-2017-9325?
CVE-2017-9325 has a severity level of high (7.5) due to its potential for unauthorized access.
How can I fix CVE-2017-9325?
To fix CVE-2017-9325, Cloudera CDH users should upgrade to a version that includes the necessary security patches.
Where can I find more information about CVE-2017-9325?
You can find more information about CVE-2017-9325 in Cloudera's security bulletin: [link here](https://www.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html)