An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cdh | Cloudera | 6.0.0 (including) | 6.0.0 (including) |
Cdh | Cloudera | 6.0.1 (including) | 6.0.1 (including) |
Cdh | Cloudera | 6.1.0 (including) | 6.1.0 (including) |