CVE-2019-7319: Cloudera Cdh

High severity, CVSS 8.3. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.

Affected products

  • Cloudera Cdh: version 6.0.0 only; version 6.0.1 only; version 6.1.0 only

Published 2019-11-26. Last modified 2026-06-17.