We found results for “”
CVE-2017-5654
Good to know:
Date: May 12, 2017
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
Language: Java
Severity Score
Related Resources (4)
Severity Score
Weakness Type (CWE)
XML Injection (aka Blind XPath Injection)
CWE-91Top Fix
Upgrade Version
Upgrade to version org.apache.ambari.contrib.views:hive-jdbc:2.4.3, org.apache.ambari.contrib.views:hive-jdbc:2.5.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |