Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Support Questions

Find answers, ask questions, and share your expertise
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

CVE-2025-3884     Cloudera Hue Directory Traversal Information Disclosure Vulnerability

avatar
Contributor

@Cloudera We have received below mentioned vulnerability from our security team. Could you please check and let us know if our Hadoop cluster is impacted by this vulnerability.
If yes the can you please provide a fix for this.

CVE-2025-3884     Cloudera Hue Directory Traversal Information Disclosure Vulnerability

CM version   :  Cloudera Enterprise 6.3.4 (#21561749)
CDH Version :  6.3.4-1.cdh6.3.4.p5552.32087246

2 REPLIES 2

avatar
Cloudera Employee

Our team is actively investigating the reported CVE. After internal discussions, we'd like to clarify that the custom Ace fork is a developer-only tool located in the tools folder. It is not included in production builds or used at runtime, so any issues in it do not impact Hue or pose a security risk. However, we will reconfirm on this and keep you updated.

avatar
Contributor

Hi,

 

Thanks for the details. Sure, please keep me updated on this. This seems critical to my security team.