CVE-2021-3167: Medium severity Cloudera Data Engineering vulnerability
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3167?
CVE-2021-3167 is a vulnerability in Cloudera Data Engineering (CDE) 1.3.0 where JWT authentication tokens are exposed to administrators in virtual cluster server logs.
How does CVE-2021-3167 affect Cloudera Data Engineering (CDE)?
CVE-2021-3167 affects Cloudera Data Engineering (CDE) 1.3.0, exposing JWT authentication tokens to administrators in virtual cluster server logs.
What is the severity of CVE-2021-3167?
The severity of CVE-2021-3167 is medium, with a CVSSv3 score of 6.5.
How can I fix CVE-2021-3167?
To fix CVE-2021-3167, upgrade to a Cloudera Data Engineering (CDE) version that is not affected by this vulnerability.
Where can I find more information about CVE-2021-3167?
You can find more information about CVE-2021-3167 in the Cloudera Data Engineering (CDE) release notes, Cloudera security bulletins, and Cloudera knowledge base.