Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2012-04-12 03:45
Updated : 2017-12-19 18:29
NVD link : CVE-2012-2230
Mitre link : CVE-2012-2230
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
cloudera
- cloudera_service_and_configuration_manager
- cloudera_manager