Description
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.9.0
References
Could your website be exposed too?
SmartScanner can check your website for Cloudera HUE Account Enumeration and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-Site Scripting in jqtree - CVE-2016-1000234
- Cross-Site Scripting in bootstrap-tagsinput - CVE-2016-1000227
- MediaElement Vulnerable to Reflected XSS - CVE-2016-4567
- chromedriver Downloads Resources over HTTP - CVE-2016-10579
You might also like:
See something that needs correcting? Let us knowUpdated November 07, 2023


