Junglewise Threat Intelligence

CVE-2016-4947: Cloudera HUE account enumeration via user autocomplete API

CVE-2016-4947 · Severity: low · CVSS 3 · Published 2022-05-17

Vendors: npm.

Executive brief

Cloudera HUE is a web-based SQL query interface used to interact with data warehouses and databases. The application exposes a user autocomplete API endpoint that does not properly restrict access, allowing unauthenticated attackers to enumerate valid user accounts. This information disclosure can facilitate targeted attacks or social engineering campaigns.

Technical details

The vulnerability is an information disclosure flaw (CWE-200) in Cloudera HUE versions 3.9.0 and earlier. The desktop/api/users/autocomplete endpoint does not require authentication and returns a list of valid user accounts in response to queries. An unauthenticated, network-based attacker can exploit this by sending requests to the endpoint to extract valid usernames. This enables account enumeration with no preconditions or user interaction required. A patch is available in versions after 3.9.0.

Affected products

  • Cloudera HUE 3.9.0 and earlier

Timeline

  • 2017-03-07: disclosed
  • 2022-05-17: advisory

References