Apache Software Foundation Ambari 1.2.4

CPE Details

Apache Software Foundation Ambari 1.2.4
1.2.4
2019-06-25
11h56 +00:00
2019-06-25
11h56 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:ambari:1.2.4:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

ambari

Version

1.2.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-50379 2024-02-27 08h27 +00:00 Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
8.8
High
CVE-2020-13924 2021-03-17 09h05 +00:00 In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
7.5
High
CVE-2020-1936 2021-03-02 09h00 +00:00 A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
6.1
Medium
CVE-2014-3582 2017-03-29 18h00 +00:00 In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.
9.8
Critical
CVE-2016-0707 2016-05-18 12h00 +00:00 The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to obtain sensitive information by reading files in the directories.
3.3
Low
CVE-2016-0731 2016-05-18 12h00 +00:00 The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.
4.9
Medium
CVE-2015-4928 2015-11-08 21h00 +00:00 Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive information by reading password fields.
4.3
CVE-2015-4940 2015-11-08 21h00 +00:00 Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information by reading this file.
2.1
CVE-2015-3186 2015-11-02 18h00 +00:00 Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.
3.5
CVE-2015-5210 2015-11-02 18h00 +00:00 Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.
5.8