cloudera CVE Vulnerabilities & Metrics

Focus on cloudera vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About cloudera Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with cloudera. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total cloudera CVEs: 43
Earliest CVE date: 12 Apr 2012, 10:45 UTC
Latest CVE date: 08 Nov 2021, 14:15 UTC

Latest CVE reference: CVE-2021-32483

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical cloudera CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.97

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 34
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS cloudera CVEs

These are the five CVEs with the highest CVSS scores for cloudera, sorted by severity first and recency.

All CVEs for cloudera

CVE-2021-32483 cloudera vulnerability CVSS: 5.0 08 Nov 2021, 14:15 UTC

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.

CVE-2021-30132 cloudera vulnerability CVSS: 7.5 08 Nov 2021, 14:15 UTC

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.

CVE-2021-32482 cloudera vulnerability CVSS: 4.3 08 Nov 2021, 13:15 UTC

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.

CVE-2021-32481 cloudera vulnerability CVSS: 4.3 08 Nov 2021, 13:15 UTC

Cloudera Hue 4.6.0 allows XSS via the type parameter.

CVE-2021-29994 cloudera vulnerability CVSS: 4.3 08 Nov 2021, 13:15 UTC

Cloudera Hue 4.6.0 allows XSS.

CVE-2021-29243 cloudera vulnerability CVSS: 4.3 08 Nov 2021, 13:15 UTC

Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.

CVE-2021-3167 cloudera vulnerability CVSS: 4.0 15 Mar 2021, 16:15 UTC

In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.

CVE-2019-14449 cloudera vulnerability CVSS: 3.5 26 Nov 2019, 17:15 UTC

An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.

CVE-2019-7319 cloudera vulnerability CVSS: 6.5 26 Nov 2019, 16:15 UTC

An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.

CVE-2018-20090 cloudera vulnerability CVSS: 6.5 26 Nov 2019, 16:15 UTC

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.

CVE-2017-7399 cloudera vulnerability CVSS: 6.5 26 Nov 2019, 16:15 UTC

Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.

CVE-2016-9271 cloudera vulnerability CVSS: 3.5 26 Nov 2019, 16:15 UTC

Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.

CVE-2018-17860 cloudera vulnerability CVSS: 6.5 26 Nov 2019, 15:15 UTC

Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.

CVE-2015-4457 cloudera vulnerability CVSS: 3.5 26 Nov 2019, 15:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.

CVE-2016-6353 cloudera vulnerability CVSS: 3.5 26 Nov 2019, 14:15 UTC

Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.

CVE-2016-5724 cloudera vulnerability CVSS: 5.0 26 Nov 2019, 14:15 UTC

Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.

CVE-2016-4572 cloudera vulnerability CVSS: 6.5 26 Nov 2019, 14:15 UTC

In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.

CVE-2016-3192 cloudera vulnerability CVSS: 4.0 26 Nov 2019, 14:15 UTC

Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.

CVE-2016-3131 cloudera vulnerability CVSS: 4.0 26 Nov 2019, 14:15 UTC

Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

CVE-2015-7831 cloudera vulnerability CVSS: 6.5 26 Nov 2019, 14:15 UTC

In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.

CVE-2015-6495 cloudera vulnerability CVSS: 5.0 26 Nov 2019, 14:15 UTC

There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.

CVE-2018-11744 cloudera vulnerability CVSS: 6.8 11 Jul 2019, 14:15 UTC

Cloudera Manager through 5.15 has Incorrect Access Control.

CVE-2017-9327 cloudera vulnerability CVSS: 4.0 03 Jul 2019, 17:15 UTC

Secret data of processes managed by CM is not secured by file permissions.

CVE-2017-9326 cloudera vulnerability CVSS: 3.5 03 Jul 2019, 17:15 UTC

The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager. The keystore file itself is not exposed.

CVE-2017-9325 cloudera vulnerability CVSS: 6.4 03 Jul 2019, 17:15 UTC

The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.

CVE-2018-11215 cloudera vulnerability CVSS: 7.5 03 Jul 2019, 16:15 UTC

Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.

CVE-2018-15665 cloudera vulnerability CVSS: 5.0 21 Jun 2019, 15:15 UTC

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.

CVE-2018-15913 cloudera vulnerability CVSS: 4.3 20 Jun 2019, 19:15 UTC

An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The validity of this parameter was not checked. As a result, the user could be automatically redirected to an attacker's external site or perform a malicious JavaScript function that results in cross-site scripting (XSS). This was fixed by not allowing any value in the returnUrl parameter with patterns such as http://, https://, //, or javascript. The only exceptions to this rule are the SAML Login/Logout URLs, which remain supported since they are explicitly configured and they are not passed via the returnUrl parameter.

CVE-2018-20091 cloudera vulnerability CVSS: 6.5 07 Jun 2019, 16:29 UTC

An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.

CVE-2018-6185 cloudera vulnerability CVSS: 5.5 07 Jun 2019, 15:29 UTC

In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in addition to those in Apache Hadoop KMS: purge and undelete. The KMS ACL values for these commands are keytrustee.kms.acl.PURGE and keytrustee.kms.acl.UNDELETE respectively. The default value for the ACLs in Key Trustee KMS 5.12.0 and 5.13.0 is "*" which allows anyone with knowledge of the name of an encryption zone key and network access to the Key Trustee KMS to make those calls against known encryption zone keys. This can result in the recovery of a previously deleted, but not purged, key (undelete) or the deletion of a key in active use (purge) resulting in loss of access to encrypted HDFS data.

CVE-2018-5798 cloudera vulnerability CVSS: 4.3 07 Jun 2019, 15:29 UTC

This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.

CVE-2018-10815 cloudera vulnerability CVSS: 4.0 24 May 2019, 17:29 UTC

An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information.

CVE-2015-8094 cloudera vulnerability CVSS: 5.8 22 May 2018, 18:29 UTC

Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.

CVE-2017-15536 cloudera vulnerability CVSS: 6.5 05 Feb 2018, 03:29 UTC

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can exploit these vulnerabilities in combination to gain root access to CDSW nodes, gain access to the CDSW database which includes Kerberos keytabs of CDSW users and bcrypt hashed passwords, and gain access to other privileged information such as session tokens, invitation tokens, and environment variables.

CVE-2016-6605 cloudera vulnerability CVSS: 5.0 10 Apr 2017, 14:59 UTC

Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

CVE-2015-4166 cloudera vulnerability CVSS: 7.5 23 Mar 2017, 20:59 UTC

Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key.

CVE-2015-4078 cloudera vulnerability CVSS: 3.5 23 Mar 2017, 20:59 UTC

Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

CVE-2015-2263 cloudera vulnerability CVSS: 2.1 23 Mar 2017, 20:59 UTC

Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.

CVE-2014-0229 cloudera vulnerability CVSS: 4.0 23 Mar 2017, 20:59 UTC

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

CVE-2013-6446 cloudera vulnerability CVSS: 3.5 23 Mar 2017, 20:59 UTC

The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.

CVE-2016-4947 cloudera vulnerability CVSS: 5.0 07 Mar 2017, 16:59 UTC

Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.

CVE-2016-4946 cloudera vulnerability CVSS: 4.3 07 Mar 2017, 16:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name or (2) Last name field in the HUE Users page.

CVE-2014-8733 cloudera vulnerability CVSS: 2.1 10 Feb 2015, 19:59 UTC

Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.

CVE-2014-0220 cloudera vulnerability CVSS: 4.0 10 Jun 2014, 14:55 UTC

Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API.

CVE-2012-2230 cloudera vulnerability CVSS: 6.5 12 Apr 2012, 10:45 UTC

Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.

CVE-2012-1574 cloudera vulnerability CVSS: 6.5 12 Apr 2012, 10:45 UTC

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.