CVE-2019-7319: Cloudera Cdh
High severity, CVSS 8.3. EPSS: 1% chance of exploitation in the next 30 days.
An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.
Affected products
- Cloudera Cdh: version 6.0.0 only; version 6.0.1 only; version 6.1.0 only
Published 2019-11-26. Last modified 2026-06-17.