Apache Software Foundation Ambari 2.6.2

CPE Details

Apache Software Foundation Ambari 2.6.2
2.6.2
2019-06-18
13h26 +00:00
2019-06-18
13h26 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:apache:ambari:2.6.2:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

ambari

Version

2.6.2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-50379 2024-02-27 08h27 +00:00 Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
8.8
Haute
CVE-2020-13924 2021-03-17 09h05 +00:00 In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
7.5
Haute
CVE-2020-1936 2021-03-02 09h00 +00:00 A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
6.1
Moyen
CVE-2018-8042 2018-07-18 15h00 +00:00 Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.
8.1
Haute