Apache / Ambari
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-51941 | Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts | HIGH | 8.8 | Jan 21, 2025 |
| CVE-2025-23196 | Apache Ambari: Code Injection Vulnerability in Ambari Alert Definition | HIGH | 8.8 | Jan 21, 2025 |
| CVE-2025-23195 | Apache Ambari: XML External Entity (XXE) Vulnerability in Ambari/Oozie | HIGH | 7.5 | Jan 21, 2025 |
| CVE-2023-50378 | Apache Ambari: Various XSS problems | MEDIUM | 5.3 | Mar 1, 2024 |
| CVE-2023-50380 | Apache Ambari: authenticated users could perform XXE to read arbitrary files on the server | MEDIUM | 6.5 | Feb 27, 2024 |
| CVE-2023-50379 | Apache Ambari: authenticated users could perform command injection to perform RCE | HIGH | 8.8 | Feb 27, 2024 |
| CVE-2022-45855 | Apache Ambari: Allows authenticated metrics consumers to perform RCE | HIGH | 8.8 | Jul 12, 2023 |
| CVE-2022-42009 | Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application. | HIGH | 8.8 | Jul 12, 2023 |
| CVE-2020-13924 | In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download f… | HIGH | 7.5 | Mar 17, 2021 |
| CVE-2020-1936 | Stored XSS in Apache Ambari | MEDIUM | 6.1 | Mar 2, 2021 |
| CVE-2018-8042 | Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store… | HIGH | 8.1 | Jul 18, 2018 |
| CVE-2018-8003 | Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides… | MEDIUM | 5.3 | May 3, 2018 |
| CVE-2017-5655 | In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are read… | MEDIUM | 6.5 | May 15, 2017 |
| CVE-2017-5654 | In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host w… | HIGH | 7.5 | May 12, 2017 |
| CVE-2017-5642 | During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. | CRITICAL | 9.8 | Apr 3, 2017 |
| CVE-2016-4976 | Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a… | MEDIUM | 5.5 | Mar 29, 2017 |
| CVE-2014-3582 | In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in… | CRITICAL | 9.8 | Mar 29, 2017 |
| CVE-2016-6807 | Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect… | CRITICAL | 9.8 | Mar 28, 2017 |
| CVE-2016-0731 | The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL confi… | MEDIUM | 4.9 | May 18, 2016 |
| CVE-2016-0707 | The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allo… | LOW | 3.3 | May 18, 2016 |
| CVE-2015-4940 | Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows loc… | LOW | 2.1 | Nov 8, 2015 |
| CVE-2015-4928 | Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proxi… | MEDIUM | 4.3 | Nov 8, 2015 |
| CVE-2015-5210 | Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a U… | MEDIUM | 5.8 | Nov 2, 2015 |
| CVE-2015-3270 | Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related… | MEDIUM | 6.5 | Nov 2, 2015 |
| CVE-2015-3186 | Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTM… | LOW | 3.5 | Nov 2, 2015 |
Showing 1 to 25 of 26 CVEs