Report a Potential Security Incident
If you believe your account has been compromised, you’ve noticed unauthorized activity, or you suspect a data breach, please contact our Incident Response Team immediately.
What to report here:
Suspected unauthorized access to your account.
Discovery of Cloudera data exposed on the public web.
Receipt of phishing attempts or scams impersonating Cloudera.
Lost or stolen hardware belonging to Cloudera.
Vulnerability Disclosure Program
Cloudera maintains a Vulnerability Disclosure Program to work with the research community. Our engineering teams work closely with researchers and the Apache community to investigate, fix, and communicate security updates for all our products. This program is unpaid; we do not offer cash rewards or bounties for submitted vulnerabilities, but we deeply appreciate and recognize the contributions of security researchers who help keep our platform and users safe. Where applicable, we may aid in submitting CVE request details.
Program Scope
This program applies specifically to Cloudera products and software releases (including Cloudera Data Platform, enterprise software, and core product code bases).
Note: Third-party vendor integrations, internal corporate infrastructure, and non-product assets are outside the direct scope of this program unless explicitly stated.
Out-of-Scope Vulnerabilities
To help our team focus on critical risks, we kindly ask that you do not submit reports for low-severity, non-actionable, or informational issues. The following are strictly out of scope:
Denial of Service (DoS/DDoS): Attacks intended to disrupt service availability or consume excessive resources.
Theoretical Attacks: Attacks requiring impossible scenarios, hypothetical exploits, or missing best-practice configurations without proof of exploitability.
Email Spoofing Issues: Missing SPF, DKIM, or DMARC records without a working exploit path.
Missing Security Headers: Lack of standard HTTP security headers (e.g., CSP, HSTS, X-Frame-Options) without a demonstrated attack.
Social Engineering / Phishing: Attacks targeting Cloudera employees, users, or contractors.
Physical Security: Any physical attacks on Cloudera facilities or data centers.
Low Severity or Info Severity: To help our team focus on critical risks, we kindly ask that you do not submit reports for low-severity or informational issues.
GPG PUBLIC KEY BLOCK
Copy and paste the key below:
How to Reach Us
We appreciate the community's help in keeping our users safe and ask that you disclose any findings to us privately before sharing them publicly.
Current Customers: Please open a case through the Support Portal.
Community Members: Please email security@cloudera.com. For extra security, we encourage you to use our GPG key to encrypt your report.
Official Security Links
To stay informed about the latest patches and known issues, you should bookmark these resources:
Cloudera Security Bulletins
Located within the documentation for specific products (like CDP or CDH), these list all "Fixed CVEs" for every release version.
Vulnerability Management Information for Customers
Request access to our Trust Portal to review Cloudera’s CVE remediation philosophy and SLAs.
