Skip to content
ambariGHSA-9g2j-5685-h44h

Apache Ambari SSRF Vulnerability

MediumCVE-2015-1775 · Published May 17, 2022 · updated Dec 6, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.ambari:ambari
Maven
>= 1.5.0, < 2.1.02.1.0
Details and references

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (`api/v1/proxy`) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2015-1775

More ambari advisories

All
DateAdvisory
May 172022Apache Ambari Improper Access Control
CVE-2016-6807Critical9.8fixed in 2.4.2
May 172022Apache Ambari reveals administrator passwords
CVE-2016-4976Medium5.5fixed in 2.4.0
May 172022Apache Ambari Open Redirect
CVE-2015-5210Mediumfixed in 2.1.2
Jan 62022Cross-site Scripting (XSS) in Apache Ambari Views
CVE-2020-1936Medium6.1fixed in 2.7.4
Jul 122023Apache Ambari Expression Language Injection vulnerability
CVE-2022-42009High8.8fixed in 2.7.7
Jul 122023Apache Ambari Expression Language Injection vulnerability
CVE-2022-45855High8.8fixed in 2.7.7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.