Skip to content
ambariGHSA-j76q-99x2-v7vq

Apache Ambari Improper Access Control

Critical9.8CVE-2016-6807 · Published May 17, 2022 · updated Nov 8, 2023

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.ambari:ambari
Maven
>= 2.4.0, < 2.4.22.4.2
Details and references

More ambari advisories

All ambari
Advisory
Apache Ambari Expression Language Injection vulnerability
High8.8Jul 12, 2023
Apache Ambari Expression Language Injection vulnerability
High8.8Jul 12, 2023
Apache Ambari SSRF Vulnerability
MediumMay 17, 2022
Apache Ambari Open Redirect
MediumMay 17, 2022
Apache Ambari reveals administrator passwords
Medium5.5May 17, 2022
Cross-site Scripting (XSS) in Apache Ambari Views
Medium6.1Jan 6, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.