PT-2021-19472 · Cloudera · Cloudera Data Engineering

Published

2021-03-15

·

Updated

2021-03-18

·

CVE-2021-3167

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cloudera Data Engineering version 1.3.0
Description The issue concerns the exposure of JWT authentication tokens to administrators in virtual cluster server logs. This affects Cloudera Data Engineering, where sensitive information is inadvertently logged, potentially allowing unauthorized access.
Recommendations For Cloudera Data Engineering version 1.3.0, consider restricting access to virtual cluster server logs to minimize the risk of exploitation, and review log configurations to prevent the logging of sensitive authentication tokens. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3167

Affected Products

Cloudera Data Engineering