In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
References
Configurations
Information
Published : 2021-03-15 09:15
Updated : 2021-03-18 13:06
NVD link : CVE-2021-3167
Mitre link : CVE-2021-3167
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
cloudera
- data_engineering