Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/48776 - | |
References | () https://ccp.cloudera.com/display/DOC/Cloudera+Security+Bulletin - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74823 - |
Information
Published : 2012-04-12 10:45
Updated : 2024-11-21 01:38
NVD link : CVE-2012-2230
Mitre link : CVE-2012-2230
CVE.ORG link : CVE-2012-2230
JSON object : View
Products Affected
cloudera
- cloudera_service_and_configuration_manager
- cloudera_manager
CWE
CWE-310
Cryptographic Issues