ambariGHSA-j76q-99x2-v7vq
Apache Ambari Improper Access Control
Critical9.8CVE-2016-6807 · Published May 17, 2022 · updated Nov 8, 2023
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.ambari:ambari Maven | >= 2.4.0, < 2.4.2 | 2.4.2 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- CVE-2016-6807
More ambari advisories
All ambari| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 122023 | Apache Ambari Expression Language Injection vulnerability | High8.8 | 2.7.7 |
| Jul 122023 | Apache Ambari Expression Language Injection vulnerability | High8.8 | 2.7.7 |
| May 172022 | Apache Ambari SSRF Vulnerability | Medium | 2.1.0 |
| May 172022 | Apache Ambari Open Redirect | Medium | 2.1.2 |
| May 172022 | Apache Ambari reveals administrator passwords | Medium5.5 | 2.4.0 |
| Jan 62022 | Cross-site Scripting (XSS) in Apache Ambari Views | Medium6.1 | 2.7.4 |