PT-2019-18526 · Cloudera · Cloudera Hue
Publicado
2019-11-26
·
Atualizado
2020-08-24
·
CVE-2019-7319
CVSS v3.1
8.3
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloudera Hue versions 6.0.0 through 6.1.0
Description
An issue was discovered in Cloudera Hue. When using certain authentication backends, such as
LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.Recommendations
For Cloudera Hue versions 6.0.0 through 6.1.0, consider disabling the creation of external users or restricting their privileges until a fix is available. As a temporary workaround, restrict access to the authentication backends
LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, and OAuthBackend to minimize the risk of exploitation.Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cloudera Hue