Описание
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cloudera:data_engineering:1.3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00408
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 6.5
github
около 3 лет назад
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
EPSS
Процентиль: 60%
0.00408
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-532