CVE-2017-9326: Cloudera Manager

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager. The keystore file itself is not exposed.

Affected products

  • Cloudera Cloudera Manager: version 5.11.0 only

Published 2019-07-03. Last modified 2026-06-17.