User Enumeration Vulnerability in Cloudera HUE by Cloudera
CVE-2016-4947
5.3MEDIUM
What is CVE-2016-4947?
Cloudera HUE versions 3.9.0 and earlier are susceptible to a user enumeration vulnerability that allows remote attackers to illicitly discover user accounts through specifically crafted API requests directed at the endpoint desktop/api/users/autocomplete. This flaw can lead to unauthorized access and information disclosure, potentially enabling attackers to launch further targeted attacks against identified users.