Cross-Site Scripting Vulnerabilities in Cloudera Manager by Cloudera
CVE-2016-4948

6.1MEDIUM

Key Information:

Vendor

Cloudera

Status
Vendor
CVE Published:
7 March 2017

What is CVE-2016-4948?

Cloudera Manager versions 5.5 and earlier are susceptible to multiple cross-site scripting vulnerabilities. These allow remote attackers to inject arbitrary web scripts or HTML into various input fields, including Template Name during template renaming, KDC Server host, Kerberos Security Realm, Kerberos Encryption Types, and several others within the advanced configuration settings of krb5.conf. Exploiting these vulnerabilities poses a significant risk, enabling attackers to manipulate user sessions and conduct malicious actions on behalf of unsuspecting users.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.