CVE-2012-2230

Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloudera:cloudera_manager:3.7.0:*:enterprise:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.0:*:free:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.1:*:enterprise:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.1:*:free:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.2:*:enterprise:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.2:*:free:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.3:*:enterprise:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.3:*:free:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.4:*:enterprise:*:*:*:*:*
cpe:2.3:a:cloudera:cloudera_manager:3.7.4:*:free:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:cloudera:cloudera_service_and_configuration_manager:3.5:*:*:*:*:*:*:*

History

21 Nov 2024, 01:38

Type Values Removed Values Added
References () http://secunia.com/advisories/48776 - () http://secunia.com/advisories/48776 -
References () https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletin - () https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletin -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/74823 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/74823 -

Information

Published : 2012-04-12 10:45

Updated : 2024-11-21 01:38


NVD link : CVE-2012-2230

Mitre link : CVE-2012-2230

CVE.ORG link : CVE-2012-2230


JSON object : View

Products Affected

cloudera

  • cloudera_service_and_configuration_manager
  • cloudera_manager
CWE
CWE-310

Cryptographic Issues