Description
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.9.0
References
- GHSA-rxfp-8jmr-xc95
- 2016.hack.lu
- web.archive.org
- CVE-2016-4947
- CWE-200
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling - CVE-2025-68620
- Denial of Service in jquery - CVE-2016-10707
- Feathers has an open redirect in OAuth callback enables account takeover - CVE-2026-27191
- chromedriver Downloads Resources over HTTP - CVE-2016-10579
- Tags:
- npm
- gethue
Anything's wrong? Let us know Last updated on November 07, 2023