PT-2017-9002 · Cloudera+1 · Cloudera Impala+3

Publicado

2017-04-10

·

Atualizado

2017-04-14

·

CVE-2016-6605

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cloudera Impala versions 5.2.0 through 5.7.2 Cloudera Impala version 5.8.0
Description The issue allows remote attackers to bypass Sentry authorization in Impala, which is part of the Cloudera Distribution of Hadoop (CDH).
Recommendations For versions 5.2.0 through 5.7.2, update to a version that includes the fix for this issue. For version 5.8.0, update to a version that includes the fix for this issue.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6605

Produtos afetados

Cloudera Distribution Of Hadoop
Cloudera Impala
Hadoop
Sentry