Local Privilege Escalation in Apache Ambari by The Apache Software Foundation
CVE-2016-0707
3.3LOW
What is CVE-2016-0707?
The Apache Ambari agent prior to version 2.1.2 has weak file permissions set on critical directories, namely /var/lib/ambari-agent/data and /var/lib/ambari-agent/keys. This configuration flaw permits local users to read sensitive files, potentially leading to unauthorized information disclosure. Proper permission settings should be implemented to safeguard these directories from unauthorized access.