An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.cloudera.com/ | vendor advisory |
https://www.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html | vendor advisory |