Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.
References
Configurations
History
21 Nov 2024, 05:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.cloudera.com/data-engineering/cloud/overview/topics/cde-service-overview.html - Product | |
References | () https://my.cloudera.com/knowledge/TSB-2020-447-Cross-Site-Request-Forgery-vulnerability-in-CDE?id=304992 - Vendor Advisory |
Information
Published : 2020-11-26 19:15
Updated : 2024-11-21 05:20
NVD link : CVE-2020-26936
Mitre link : CVE-2020-26936
CVE.ORG link : CVE-2020-26936
JSON object : View
Products Affected
cloudera
- data_engineering
CWE
CWE-352
Cross-Site Request Forgery (CSRF)