Directory Traversal Vulnerability in Apache Ambari
CVE-2018-8003

5.3MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
3 May 2018

Summary

Apache Ambari, across multiple versions up to 2.6.1, suffers from a directory traversal vulnerability that allows unauthenticated users to send crafted HTTP requests. These requests can grant unauthorized read-only access to files located on the host's filesystem, accessible by the user under whom the Ambari Server is running. While direct network access is necessary for this attack to be successful, instances of Ambari that are properly shielded by firewalls or located in secure network zones are less likely to be exploited.

Affected Version(s)

Apache Ambari Apache Ambari 1.4.0 to 2.6.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.