CVE-2016-3131: Cloudera Cdh

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

Affected products

  • Cloudera Cdh: from 5.0.0, before 5.3.10 (fixed in 5.3.10); from 5.4.0, before 5.4.10 (fixed in 5.4.10); from 5.5.0, before 5.5.4 (fixed in 5.5.4); version 5.6.0 only

Published 2019-11-26. Last modified 2026-06-17.