CVE-2021-32482: XSS
Published Nov 8, 2021
·Updated
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
Affected Software
5 affected components
Cloudera Cloudera Manager>=5.0.0<=5.16.2
Cloudera Cloudera Manager>=6.0.0<=6.3.4
Cloudera Cloudera Manager>=7.1.0<=7.1.4
Cloudera Cloudera Manager>=7.2.0<=7.2.4
Cloudera Cloudera Manager>=7.3.0<=7.3.4
Event History
Nov 8, 2021
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Cloudera Manager XSS vulnerability?
The vulnerability ID for the Cloudera Manager XSS vulnerability is CVE-2021-32482.
2
How does Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allow XSS?
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
3
What is the severity of CVE-2021-32482?
The severity of CVE-2021-32482 is medium with a CVSS score of 6.1.
4
Which versions of Cloudera Manager are affected by CVE-2021-32482?
Cloudera Manager versions 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x are affected by CVE-2021-32482.
5
How can I fix the Cloudera Manager XSS vulnerability?
To fix the Cloudera Manager XSS vulnerability, it is recommended to upgrade to a patched version of Cloudera Manager.