CVE-2018-20090: High severity cloudera data science workbench vulnerability
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20090?
CVE-2018-20090 is a vulnerability discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2 that allows authenticated users to bypass project permission checks and gain read-write access to any project folder.
How does CVE-2018-20090 affect Cloudera Data Science Workbench?
CVE-2018-20090 affects Cloudera Data Science Workbench versions 1.4.0 through 1.4.2, allowing authenticated users to bypass project permission checks.
What is the severity of CVE-2018-20090?
CVE-2018-20090 has a severity keyword of 'high' and a severity value of 8.3.
How can authenticated users exploit CVE-2018-20090?
Authenticated users can exploit CVE-2018-20090 to gain read-write access to any project folder in Cloudera Data Science Workbench.
How do I fix CVE-2018-20090?
To fix CVE-2018-20090, it is recommended to upgrade to a version of Cloudera Data Science Workbench that is not affected by the vulnerability. Refer to the Cloudera security bulletin for more details.