Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://issues.cloudera.org/browse/HUE-3626 | issue tracking patch vendor advisory |
http://cloudera.github.io/hue/latest/release-notes/release-notes-3.10.0.html | third party advisory release notes |
https://github.com/cloudera/hue/pull/346 | third party advisory |
https://www.harmfultrust.com/p/advisories.html | third party advisory exploit |