Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.
2015-02-10T19:59:00.053
2025-04-12T10:46:40.837
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | cloudera | cloudera_manager | 5.2.0 | Yes |
| Application | cloudera | cloudera_manager | 5.2.1 | Yes |
| Application | cloudera | cloudera_manager | 5.3.0 | Yes |