Executive brief
Cloudera HUE is a web-based SQL query interface used to interact with data warehouses and databases. The application exposes a user autocomplete API endpoint that does not properly restrict access, allowing unauthenticated attackers to enumerate valid user accounts. This information disclosure can facilitate targeted attacks or social engineering campaigns.
Technical details
The vulnerability is an information disclosure flaw (CWE-200) in Cloudera HUE versions 3.9.0 and earlier. The desktop/api/users/autocomplete endpoint does not require authentication and returns a list of valid user accounts in response to queries. An unauthenticated, network-based attacker can exploit this by sending requests to the endpoint to extract valid usernames. This enables account enumeration with no preconditions or user interaction required. A patch is available in versions after 3.9.0.
Affected products
- Cloudera HUE 3.9.0 and earlier
Timeline
- 2017-03-07: disclosed
- 2022-05-17: advisory