CVE-2012-2230: Cloudera Manager
Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.
Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.
Affected products
- Cloudera Cloudera Manager: version 3.7.0 only; version 3.7.1 only; version 3.7.2 only; version 3.7.3 only; version 3.7.4 only
- Cloudera Cloudera Service And Configuration Manager: version 3.5 only
Published 2012-04-12. Last modified 2026-06-16.