Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.
2017-03-23T20:59:00.297
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 3.3 (LOW)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | cloudera | cloudera_manager | 4.0.0 | Yes |
| Application | cloudera | cloudera_manager | 4.0.1 | Yes |
| Application | cloudera | cloudera_manager | 4.0.2 | Yes |
| Application | cloudera | cloudera_manager | 4.0.3 | Yes |
| Application | cloudera | cloudera_manager | 4.0.4 | Yes |
| Application | cloudera | cloudera_manager | 4.1.0 | Yes |
| Application | cloudera | cloudera_manager | 4.1.1 | Yes |
| Application | cloudera | cloudera_manager | 4.1.2 | Yes |
| Application | cloudera | cloudera_manager | 4.1.3 | Yes |
| Application | cloudera | cloudera_manager | 4.1.4 | Yes |
| Application | cloudera | cloudera_manager | 4.5.0 | Yes |
| Application | cloudera | cloudera_manager | 4.5.1 | Yes |
| Application | cloudera | cloudera_manager | 4.5.2 | Yes |
| Application | cloudera | cloudera_manager | 4.5.3 | Yes |
| Application | cloudera | cloudera_manager | 4.5.4 | Yes |
| Application | cloudera | cloudera_manager | 4.6.0 | Yes |
| Application | cloudera | cloudera_manager | 4.6.1 | Yes |
| Application | cloudera | cloudera_manager | 4.6.2 | Yes |
| Application | cloudera | cloudera_manager | 4.6.3 | Yes |
| Application | cloudera | cloudera_manager | 4.7.0 | Yes |
| Application | cloudera | cloudera_manager | 4.7.1 | Yes |
| Application | cloudera | cloudera_manager | 4.7.2 | Yes |
| Application | cloudera | cloudera_manager | 4.7.3 | Yes |
| Application | cloudera | cloudera_manager | 5.0.0 | Yes |
| Application | cloudera | cloudera_manager | 5.0.0 | Yes |
| Application | cloudera | cloudera_manager | 5.0.0 | Yes |
| Application | cloudera | cloudera_manager | 5.0.1 | Yes |
| Application | cloudera | cloudera_manager | 5.0.2 | Yes |
| Application | cloudera | cloudera_manager | 5.0.5 | Yes |
| Application | cloudera | cloudera_manager | 5.1.0 | Yes |
| Application | cloudera | cloudera_manager | 5.1.1 | Yes |
| Application | cloudera | cloudera_manager | 5.1.2 | Yes |
| Application | cloudera | cloudera_manager | 5.1.3 | Yes |
| Application | cloudera | cloudera_manager | 5.1.4 | Yes |
| Application | cloudera | cloudera_manager | 5.2.0 | Yes |
| Application | cloudera | cloudera_manager | 5.2.1 | Yes |
| Application | cloudera | cloudera_manager | 5.2.2 | Yes |
| Application | cloudera | cloudera_manager | 5.2.4 | Yes |
| Application | cloudera | cloudera_manager | 5.3.0 | Yes |
| Application | cloudera | cloudera_manager | 5.3.1 | Yes |
| Application | cloudera | cloudera_manager | 5.3.2 | Yes |