An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.cloudera.com | vendor advisory |
https://www.cloudera.com/documentation/other/security-bulletins/topics/Security-Bulletin.html | vendor advisory |