CVE-2021-3167
MEDIUMCVSS 6.5/10EPSS 1.11%
Last modified
CVE-2021-3167 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudera | Data Engineering | 1.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3167?
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
How severe is CVE-2021-3167?
CVE-2021-3167 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.11% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3167?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-3166An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devi…7.5
- CVE-2021-31660RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5…7.5
- CVE-2021-31661RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba…7.5
- CVE-2021-31662RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aa…7.5
- CVE-2021-31663RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d749853…7.5
- CVE-2021-31664RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9…7.5
- CVE-2021-31671pgsync before 0.6.7 is affected by Information Disclosure of…7.5
- CVE-2021-31673A Dom-based Cross-site scripting (XSS) vulnerability at regi…6.1
- CVE-2021-31674Cyclos 4 PRO 4.14.7 and before does not validate user input …6.1
- CVE-2021-31676A reflected XSS was discovered in PESCMS-V2.3.3. When combin…6.1
- CVE-2021-31677An issue was discovered in PESCMS-V2.3.3. There is a CSRF vu…6.5
- CVE-2021-31678An issue was discovered in PESCMS-V2.3.3. There is a CSRF vu…6.5
Are you affected by CVE-2021-3167?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
