CVE-2018-17860: High severity cloudera hadoop vulnerability
Published Nov 26, 2019
·Updated
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
Affected Software
5 affected components
Cloudera CDH>=5.0.0<=5.14.0
Cloudera CDH=5.15.0
Cloudera CDH=5.15.1
Cloudera CDH=6.0.0
Cloudera CDH=6.0.1
Event History
Nov 26, 2019
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
Description
Frequently Asked Questions
1
What is CVE-2018-17860?
CVE-2018-17860 is a vulnerability in Cloudera CDH that allows insecure permissions because ALL cannot be revoked.
2
How does CVE-2018-17860 affect Cloudera CDH?
CVE-2018-17860 affects Cloudera CDH versions 5.x through 5.15.1 and 6.x through 6.0.1.
3
What is the severity of CVE-2018-17860?
CVE-2018-17860 has a severity level of 7.2 (high).
4
How can I fix CVE-2018-17860 in Cloudera CDH?
To fix CVE-2018-17860 in Cloudera CDH, you should update to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2018-17860?
You can find more information about CVE-2018-17860 in the Cloudera CDH documentation and security bulletins.