Directory Traversal Vulnerability in Apache Ambari
CVE-2018-8003
5.3MEDIUM
What is CVE-2018-8003?
Apache Ambari, across multiple versions up to 2.6.1, suffers from a directory traversal vulnerability that allows unauthenticated users to send crafted HTTP requests. These requests can grant unauthorized read-only access to files located on the host's filesystem, accessible by the user under whom the Ambari Server is running. While direct network access is necessary for this attack to be successful, instances of Ambari that are properly shielded by firewalls or located in secure network zones are less likely to be exploited.
Affected Version(s)
Apache Ambari Apache Ambari 1.4.0 to 2.6.1