Superuser Privilege Escalation in Cloudera Hue by External Users
CVE-2019-7319
8.3HIGH
What is CVE-2019-7319?
A security issue has been identified in Cloudera Hue versions 6.0.0 to 6.1.0, where external users can be inadvertently granted superuser privileges through various authentication backends, including LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, and OAuthBackend. This misconfiguration can lead to unauthorized access and potential control over sensitive operations within Hue. Organizations utilizing these versions are advised to review their authentication settings to mitigate the risks associated with this vulnerability.