CVE-2015-8094: Medium severity cloudera hue vulnerability
Published May 22, 2018
·Updated
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
Affected Software
1 affected component
Cloudera Hue<3.10.0
Remediation
Patch Available
Event History
May 22, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is CVE-2015-8094?
CVE-2015-8094 is an open redirect vulnerability in Cloudera HUE before version 3.10.0.
2
How does CVE-2015-8094 work?
CVE-2015-8094 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks by manipulating the next parameter in a URL.
3
What is the severity level of CVE-2015-8094?
The severity level of CVE-2015-8094 is medium with a CVSS score of 6.1.
4
How can I fix the CVE-2015-8094 vulnerability?
To fix the CVE-2015-8094 vulnerability, update Cloudera HUE to version 3.10.0 or later.
5
Where can I find more information about CVE-2015-8094?
You can find more information about CVE-2015-8094 in the Cloudera HUE release notes for version 3.10.0.