Information Disclosure in Cloudera Data Science Workbench by Cloudera
CVE-2018-15665

5.3MEDIUM

Key Information:

Vendor

Cloudera

Vendor
CVE Published:
21 June 2019

What is CVE-2018-15665?

An issue was identified in Cloudera Data Science Workbench that enables unauthenticated users to enumerate user accounts. This vulnerability poses a security risk as it can lead to unauthorized access to sensitive information, thereby compromising user data privacy. Organizations utilizing affected versions should prioritize applying available patches to mitigate the risk. For detailed information, refer to Cloudera's security bulletins.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.