Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cloudera Data Science Workbench SQL注入漏洞
Vulnerability Description
Cloudera Data Science Workbench(CDSW)是Cloudera公司的一套数据科学平台。该平台为企业提供快速、简易且安全的自助式数据科学支持。 Cloudera CDSW 1.4.0版本至1.4.2版本中存在SQL注入漏洞。该漏洞源于基于数据库的应用缺少对外部输入SQL语句的验证。攻击者可利用该漏洞执行非法SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A