CVE-2020-26936: CSRF
Published Nov 26, 2020
·Updated
Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.
Affected Software
1 affected component
Cloudera Data Engineering<1.1
Event History
Nov 26, 2020
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26936?
CVE-2020-26936 refers to a Cross-Site Request Forgery (CSRF) vulnerability in Cloudera Data Engineering (CDE) before version 1.1.
2
How severe is CVE-2020-26936?
CVE-2020-26936 has a severity score of 8.8, which is considered high.
3
How does CVE-2020-26936 impact Cloudera Data Engineering (CDE)?
CVE-2020-26936 allows an attacker to perform CSRF attacks on Cloudera Data Engineering (CDE) before version 1.1.
4
How can I fix CVE-2020-26936?
To fix CVE-2020-26936, update Cloudera Data Engineering (CDE) to version 1.1 or later.
5
Where can I find more information about CVE-2020-26936?
You can find more information about CVE-2020-26936 in the official Cloudera Data Engineering (CDE) documentation and the Cloudera knowledge base.