CVE-2018-8042
- EPSS 0.69%
- Published 18.07.2018 15:29:00
- Last modified 21.11.2024 04:13:09
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.
CVE-2018-8003
- EPSS 1.9%
- Published 03.05.2018 23:29:00
- Last modified 21.11.2024 04:13:04
Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host the Ambari Server runs on that ...
CVE-2017-5655
- EPSS 0.15%
- Published 15.05.2017 14:29:00
- Last modified 20.04.2025 01:37:25
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.
CVE-2017-5654
- EPSS 0.91%
- Published 12.05.2017 21:29:00
- Last modified 20.04.2025 01:37:25
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
CVE-2017-5642
- EPSS 0.77%
- Published 03.04.2017 16:59:00
- Last modified 20.04.2025 01:37:25
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
CVE-2016-4976
- EPSS 0.08%
- Published 29.03.2017 20:59:00
- Last modified 20.04.2025 01:37:25
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
CVE-2014-3582
- EPSS 0.34%
- Published 29.03.2017 20:59:00
- Last modified 20.04.2025 01:37:25
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.
CVE-2016-6807
- EPSS 0.84%
- Published 28.03.2017 20:59:00
- Last modified 20.04.2025 01:37:25
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari A...
CVE-2016-0731
- EPSS 0.2%
- Published 18.05.2016 14:59:03
- Last modified 12.04.2025 10:46:40
The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.
CVE-2016-0707
- EPSS 0.06%
- Published 18.05.2016 14:59:01
- Last modified 12.04.2025 10:46:40
The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to obtain sensitive information by reading files in the directories.