Описание
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-3167
- https://docs.cloudera.com/data-engineering/cloud/release-notes/topics/cde-general-known-issues.html
- https://docs.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html
- https://my.cloudera.com/knowledge/TSB-2021-466-CDE-authentication-tokens-exposed-in-pod-and?id=310163
Связанные уязвимости
CVSS3: 6.5
nvd
больше 4 лет назад
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.