Open Redirect Flaw in Cloudera HUE Affects User Security
CVE-2015-8094

6.1MEDIUM

Key Information:

Vendor

Cloudera

Status
Vendor
CVE Published:
22 May 2018

What is CVE-2015-8094?

An open redirect vulnerability exists in Cloudera HUE versions prior to 3.10.0. This flaw enables remote attackers to manipulate URLs, redirecting users to arbitrary and potentially malicious websites. By leveraging this vulnerability, attackers can execute phishing attacks, tricking users into revealing sensitive information. It is crucial for organizations using affected versions of HUE to apply the necessary updates to protect against this risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2015-8094 : Open Redirect Flaw in Cloudera HUE Affects User Security