An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cdh | Cloudera | 6.0.0 (including) | 6.0.0 (including) |
| Cdh | Cloudera | 6.0.1 (including) | 6.0.1 (including) |
| Cdh | Cloudera | 6.1.0 (including) | 6.1.0 (including) |