Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename parameter to /cmf/process/<process_id>/logs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cloudera Manager 信息泄露漏洞
Vulnerability Description
Cloudera Manager是美国Cloudera公司的一套Hadoop数据管理软件。该软件支持创建集群、身份验证、数据备份和恢复等。 Cloudera Manager 5.5及之前的版本中存在安全漏洞。远程攻击者可通过向/cmf/process/<process_id>/logs发送带有stderr.log或stdout.log值的‘filename’参数利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A