Directory Traversal Vulnerability in Apache Ambari
CVE-2018-8003
5.3MEDIUM
Summary
Apache Ambari, across multiple versions up to 2.6.1, suffers from a directory traversal vulnerability that allows unauthenticated users to send crafted HTTP requests. These requests can grant unauthorized read-only access to files located on the host's filesystem, accessible by the user under whom the Ambari Server is running. While direct network access is necessary for this attack to be successful, instances of Ambari that are properly shielded by firewalls or located in secure network zones are less likely to be exploited.
Affected Version(s)
Apache Ambari Apache Ambari 1.4.0 to 2.6.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved