Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloudera_manager | Cloudera | 4.0.0 (including) | 4.0.0 (including) |
Cloudera_manager | Cloudera | 4.0.1 (including) | 4.0.1 (including) |
Cloudera_manager | Cloudera | 4.0.2 (including) | 4.0.2 (including) |
Cloudera_manager | Cloudera | 4.0.3 (including) | 4.0.3 (including) |
Cloudera_manager | Cloudera | 4.0.4 (including) | 4.0.4 (including) |
Cloudera_manager | Cloudera | 4.1.0 (including) | 4.1.0 (including) |
Cloudera_manager | Cloudera | 4.1.1 (including) | 4.1.1 (including) |
Cloudera_manager | Cloudera | 4.1.2 (including) | 4.1.2 (including) |
Cloudera_manager | Cloudera | 4.1.3 (including) | 4.1.3 (including) |
Cloudera_manager | Cloudera | 4.1.4 (including) | 4.1.4 (including) |
Cloudera_manager | Cloudera | 4.5.0 (including) | 4.5.0 (including) |
Cloudera_manager | Cloudera | 4.5.1 (including) | 4.5.1 (including) |
Cloudera_manager | Cloudera | 4.5.2 (including) | 4.5.2 (including) |
Cloudera_manager | Cloudera | 4.5.3 (including) | 4.5.3 (including) |
Cloudera_manager | Cloudera | 4.5.4 (including) | 4.5.4 (including) |
Cloudera_manager | Cloudera | 4.6.0 (including) | 4.6.0 (including) |
Cloudera_manager | Cloudera | 4.6.1 (including) | 4.6.1 (including) |
Cloudera_manager | Cloudera | 4.6.2 (including) | 4.6.2 (including) |
Cloudera_manager | Cloudera | 4.6.3 (including) | 4.6.3 (including) |
Cloudera_manager | Cloudera | 4.7.0 (including) | 4.7.0 (including) |
Cloudera_manager | Cloudera | 4.7.1 (including) | 4.7.1 (including) |
Cloudera_manager | Cloudera | 4.7.2 (including) | 4.7.2 (including) |
Cloudera_manager | Cloudera | 4.7.3 (including) | 4.7.3 (including) |
Cloudera_manager | Cloudera | 5.0.0 (including) | 5.0.0 (including) |
Cloudera_manager | Cloudera | 5.0.0-beta1 (including) | 5.0.0-beta1 (including) |
Cloudera_manager | Cloudera | 5.0.0-beta2 (including) | 5.0.0-beta2 (including) |
Cloudera_manager | Cloudera | 5.0.1 (including) | 5.0.1 (including) |
Cloudera_manager | Cloudera | 5.0.2 (including) | 5.0.2 (including) |
Cloudera_manager | Cloudera | 5.0.5 (including) | 5.0.5 (including) |
Cloudera_manager | Cloudera | 5.1.0 (including) | 5.1.0 (including) |
Cloudera_manager | Cloudera | 5.1.1 (including) | 5.1.1 (including) |
Cloudera_manager | Cloudera | 5.1.2 (including) | 5.1.2 (including) |
Cloudera_manager | Cloudera | 5.1.3 (including) | 5.1.3 (including) |
Cloudera_manager | Cloudera | 5.1.4 (including) | 5.1.4 (including) |
Cloudera_manager | Cloudera | 5.2.0 (including) | 5.2.0 (including) |
Cloudera_manager | Cloudera | 5.2.1 (including) | 5.2.1 (including) |
Cloudera_manager | Cloudera | 5.2.2 (including) | 5.2.2 (including) |
Cloudera_manager | Cloudera | 5.2.4 (including) | 5.2.4 (including) |
Cloudera_manager | Cloudera | 5.3.0 (including) | 5.3.0 (including) |
Cloudera_manager | Cloudera | 5.3.1 (including) | 5.3.1 (including) |
Cloudera_manager | Cloudera | 5.3.2 (including) | 5.3.2 (including) |