CVE-2018-20091
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.
Se encontró una vulnerabilidad de inyección SQL en Cloudera Data Science Workbench (CDSW) versión 1.4.0 hasta la versión 1.4.2. Esto permitiría a cualquier usuario autenticado ejecutar consultas arbitrarias en la base de datos interna de CDSW. La base de datos contiene información de contacto del usuario, contraseñas cifradas de CDSW (en el caso de la autenticación local), claves de API y fichas de claves de Kerberos almacenadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-12 CVE Reserved
- 2019-06-07 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html | 2019-06-10 |
URL | Date | SRC |
---|---|---|
https://www.cloudera.com/products/data-science-and-engineering/data-science-workbench.html | 2019-06-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudera Search vendor "Cloudera" | Data Science Workbench Search vendor "Cloudera" for product "Data Science Workbench" | >= 1.4.0 <= 1.4.2 Search vendor "Cloudera" for product "Data Science Workbench" and version " >= 1.4.0 <= 1.4.2" | - |
Affected
|