Vulnerabilities/

Cloudera HUE Account Enumeration

Severity:
Medium

Description

Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
gethue
Anything's wrong? Let us know Last updated on November 07, 2023

This issue is available in SmartScanner Professional

See Pricing