Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability

Vulnerability

A directory traversal vulnerability allowing information disclosure has been identified in the Ace Editor component of Cloudera Hue. This issue arises from inadequate validation of user-supplied paths before they are used in file operations, enabling remote attackers to access sensitive information within the context of the service account. Notably, authentication is not required to exploit this vulnerability.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information from the affected Cloudera Hue installation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.