User Account Enumeration Vulnerability in Cloudera HUE 3.9.0 and Earlier

User Account Enumeration Vulnerability in Cloudera HUE 3.9.0 and Earlier

CVE-2016-4947 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.

Learn more about our Cis Benchmark Audit For Desktop Software.