CVE-2019-7319: High severity cloudera hadoop vulnerability
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-7319.
What is the severity level of CVE-2019-7319?
The severity level of CVE-2019-7319 is high.
What is the affected software for CVE-2019-7319?
The affected software for CVE-2019-7319 is Cloudera Hue 6.0.0 through 6.1.0.
How can external users be created with superuser privileges?
External users can be created with superuser privileges when using one of the following authentication backends in Cloudera Hue 6.0.0 through 6.1.0: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend.
Where can I find more information about CVE-2019-7319?
You can find more information about CVE-2019-7319 in the Cloudera Security Bulletin: https://docs.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html#concept_o2p_hjm_33b.