Skip to main content

Vendor/product archive

apache / ambari CVEs

Beta · best-effort

26 CVEs tagged to apache / ambari3 Critical, 9 High, 11 Medium, 3 Low, 0 Unrated.

CVE-2025-23196

Published Jan 21, 2025

A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability aris…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-23195

Published Jan 21, 2025

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure p…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-51941

Published Jan 21, 2025

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50378

Published Mar 1, 2024

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited to perform unauthorized action…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50380

Published Feb 27, 2024

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Schedul…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50379

Published Feb 27, 2024

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45855

Published Jul 12, 2023

SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42009

Published Jul 12, 2023

SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to u…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13924

Published Mar 17, 2021

In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1936

Published Mar 2, 2021

A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8042

Published Jul 18, 2018

Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled f…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8003

Published May 3, 2018

Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5655

Published May 15, 2017

In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user aut…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5654

Published May 12, 2017

In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5642

Published Apr 3, 2017

During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4976

Published Mar 29, 2017

Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3582

Published Mar 29, 2017

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6807

Published Mar 28, 2017

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying syst…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-0731

Published May 18, 2016

The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0707

Published May 18, 2016

The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to ob…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4940

Published Nov 8, 2015

Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain s…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4928

Published Nov 8, 2015

Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to ob…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5210

Published Nov 2, 2015

Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3270

Published Nov 2, 2015

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing password…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3186

Published Nov 2, 2015

Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2