Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cloudera

First CVE: Apr 12, 2012Active for: 14 yearsTotal CVEs: 52
20.2
VTI Score
Low

Cloudera's vulnerability footprint spans a focused but prominent portfolio of big-data and analytics platforms, including Cloudera Manager, CDH, Hue, and Data Science Workbench, that serve as central control and processing layers in enterprise data infrastructure. Vulnerabilities affecting the vendor reach serious severity with a meaningful tendency toward critical outcomes, and recur through weakness classes including exposure of sensitive information, cross-site scripting, improper privilege management, and authorization flaws that are characteristic of complex, multi-tenant distributed systems with layered administrative interfaces. The concentration of these flaws in management and web-facing components reflects the vendor's role in orchestrating access to sensitive data repositories and cluster resources across large deployments. Defenders should prioritize this vendor's patches for environments where Cloudera products control data access or cluster configuration, as the recurring authorization and information-disclosure patterns directly threaten data confidentiality and integrity. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
52
Total CVEs
More Total CVEs than 98% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cloudera over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2012
14 years ago
Most Recent CVE
May 22, 2025
428 days ago

Products(13 total)

Top CVEs

Signals from CVEs in this vendor scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11215CRITICAL
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.
Jul 3, 20199.831NONO
CVE-2021-30132CRITICAL
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
Nov 8, 20219.830NONO
CVE-2018-20091CRITICAL
An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDS
Jun 7, 20199.930NONO
CVE-2025-3884HIGH
Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installat
May 22, 20257.526NONO
CVE-2016-4572HIGH
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
Nov 26, 20198.825NONO
CVE-2016-4950HIGH
Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions.
Mar 7, 20177.525NONO
CVE-2012-1574MEDIUM
The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through C
Apr 12, 20126.525NONO
CVE-2019-7319HIGH
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBack
Nov 26, 20198.324NONO
CVE-2018-20090HIGH
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any pr
Nov 26, 20198.324NONO
CVE-2018-11744HIGH
Cloudera Manager through 5.15 has Incorrect Access Control.
Jul 11, 20198.124NONO
View all 52 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products52 CVEs
52%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.9%)
Network47 (90.4%)
Unknown4 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (84.6%)
High4 (7.7%)
Unknown4 (7.7%)
User Interaction
None34 (65.4%)
Unknown4 (7.7%)
Required14 (26.9%)
Privileges Required
Low21 (40.4%)
High2 (3.8%)
None25 (48.1%)
Unknown4 (7.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudera.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cloudera — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cloudera's Products

View all 4 CNAs →

Top CWEs