Description
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete
.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.9.0
References
- GHSA-rxfp-8jmr-xc95
- 2016.hack.lu
- web.archive.org
- CVE-2016-4947
- CWE-200
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- Command Injection Vulnerability - CVE-2021-21315
- Cross-Site Scripting in exceljs - CVE-2018-16459
- Sensitive data exposure in NATS - CVE-2020-26149
- Cross-Site Scripting in i18next - CVE-2017-16008
- Tags:
- npm
- gethue
Anything's wrong? Let us know Last updated on November 07, 2023