Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler.
References
Link | Resource |
---|---|
https://docs.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html#tsb_165 | Vendor Advisory |
Configurations
Information
Published : 2019-11-26 06:15
Updated : 2019-12-12 06:31
NVD link : CVE-2016-6353
Mitre link : CVE-2016-6353
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
cloudera
- cdh