PT-2019-18526 · Cloudera · Cloudera Hue
Published
2019-11-26
·
Updated
2020-08-24
·
CVE-2019-7319
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloudera Hue versions 6.0.0 through 6.1.0
Description
An issue was discovered in Cloudera Hue. When using certain authentication backends, such as
LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.Recommendations
For Cloudera Hue versions 6.0.0 through 6.1.0, consider disabling the creation of external users or restricting their privileges until a fix is available. As a temporary workaround, restrict access to the authentication backends
LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, and OAuthBackend to minimize the risk of exploitation.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudera Hue