CVE-2019-14449: XSS
Published Nov 26, 2019
·Updated
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.
Affected Software
4 affected components
Cloudera Cloudera Manager>=5.0.0<5.16.2
Cloudera Cloudera Manager=6.0.0
Cloudera Cloudera Manager=6.0.1
Cloudera Cloudera Manager=6.1.0
Event History
Nov 26, 2019
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue in Cloudera Manager?
The vulnerability ID is CVE-2019-14449.
2
What is the severity rating of CVE-2019-14449?
CVE-2019-14449 has a severity rating of medium (5.4).
3
What is the description of this vulnerability?
The vulnerability allows malicious impala queries to result in Cross Site Scripting (XSS) when viewed within Cloudera Manager.
4
How does CVE-2019-14449 affect Cloudera Manager?
CVE-2019-14449 affects Cloudera Manager versions 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1.
5
How can I fix this vulnerability in Cloudera Manager?
To fix this vulnerability, you should upgrade your Cloudera Manager to version 5.16.2, 6.0.2, or 6.1.1.