First published: Mon Nov 08 2021(Updated: )
Cloudera Hue 4.6.0 allows XSS via the type parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudera Hue | =4.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32481 is a vulnerability in Cloudera Hue 4.6.0 that allows for cross-site scripting (XSS) attacks via the type parameter.
The severity of CVE-2021-32481 is medium with a CVSS score of 6.1.
CVE-2021-32481 allows attackers to perform cross-site scripting (XSS) attacks on Cloudera Hue 4.6.0 by exploiting the type parameter.
To fix CVE-2021-32481, it is recommended to upgrade to a patched version of Cloudera Hue.
More information about CVE-2021-32481 can be found in the Cloudera Security Bulletin and the Cloudera Knowledge article linked in the references.