ambariGHSA-w3p6-94x2-xcvm
Apache Ambari Open Redirect
MediumCVE-2015-5210 · Published May 17, 2022 · updated Dec 6, 2024
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.ambari:ambari Maven | >= 1.7.0, < 2.1.2 | 2.1.2 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-601
- Also known as
- CVE-2015-5210
More ambari advisories
All ambari| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 122023 | Apache Ambari Expression Language Injection vulnerability | High8.8 | 2.7.7 |
| Jul 122023 | Apache Ambari Expression Language Injection vulnerability | High8.8 | 2.7.7 |
| May 172022 | Apache Ambari SSRF Vulnerability | Medium | 2.1.0 |
| May 172022 | Apache Ambari reveals administrator passwords | Medium5.5 | 2.4.0 |
| May 172022 | Apache Ambari Improper Access Control | Critical9.8 | 2.4.2 |
| Jan 62022 | Cross-site Scripting (XSS) in Apache Ambari Views | Medium6.1 | 2.7.4 |