First published: Fri Jun 21 2019(Updated: )
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera Data Science Workbench | >=1.2.0<=1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15665 is a vulnerability in Cloudera Data Science Workbench (CDSW) versions 1.2.x through 1.4.0 that allows unauthenticated users to obtain a list of user accounts.
The severity of CVE-2018-15665 is medium with a CVSS score of 5.3.
CVE-2018-15665 affects Cloudera Data Science Workbench (CDSW) versions 1.2.x through 1.4.0, allowing unauthenticated users to obtain a list of user accounts.
Yes, the fix for CVE-2018-15665 is to upgrade Cloudera Data Science Workbench (CDSW) to a version above 1.4.0.
You can find more information about CVE-2018-15665 on the Cloudera website and their security bulletins documentation.