Cloudera's vulnerability footprint spans a focused but prominent portfolio of big-data and analytics platforms, including Cloudera Manager, CDH, Hue, and Data Science Workbench, that serve as central control and processing layers in enterprise data infrastructure. Vulnerabilities affecting the vendor reach serious severity with a meaningful tendency toward critical outcomes, and recur through weakness classes including exposure of sensitive information, cross-site scripting, improper privilege management, and authorization flaws that are characteristic of complex, multi-tenant distributed systems with layered administrative interfaces. The concentration of these flaws in management and web-facing components reflects the vendor's role in orchestrating access to sensitive data repositories and cluster resources across large deployments. Defenders should prioritize this vendor's patches for environments where Cloudera products control data access or cluster configuration, as the recurring authorization and information-disclosure patterns directly threaten data confidentiality and integrity. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudera over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11215CRITICAL Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors. | Jul 3, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-30132CRITICAL Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. | Nov 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-20091CRITICAL An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDS | Jun 7, 2019 | 9.9 | 30 | NO | NO |
CVE-2025-3884HIGH Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installat | May 22, 2025 | 7.5 | 26 | NO | NO |
CVE-2016-4572HIGH In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. | Nov 26, 2019 | 8.8 | 25 | NO | NO |
CVE-2016-4950HIGH Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions. | Mar 7, 2017 | 7.5 | 25 | NO | NO |
CVE-2012-1574MEDIUM The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through C | Apr 12, 2012 | 6.5 | 25 | NO | NO |
CVE-2019-7319HIGH An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBack | Nov 26, 2019 | 8.3 | 24 | NO | NO |
CVE-2018-20090HIGH An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any pr | Nov 26, 2019 | 8.3 | 24 | NO | NO |
CVE-2018-11744HIGH Cloudera Manager through 5.15 has Incorrect Access Control. | Jul 11, 2019 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudera.
Media articles that mention a CVE ID that affects a product developed by Cloudera — matched by CVE ID, not by vendor name.