CVE Vulnerabilities

CVE-2015-1775

Published: Nov 02, 2015 | Modified: Nov 04, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

Affected Software

Name Vendor Start Version End Version
Ambari Apache 1.5.0 (including) 1.5.0 (including)
Ambari Apache 1.5.1 (including) 1.5.1 (including)
Ambari Apache 1.6.0 (including) 1.6.0 (including)
Ambari Apache 1.6.1 (including) 1.6.1 (including)
Ambari Apache 1.7.0 (including) 1.7.0 (including)
Ambari Apache 2.0.0 (including) 2.0.0 (including)
Ambari Apache 2.0.1 (including) 2.0.1 (including)
Ambari Apache 2.0.2 (including) 2.0.2 (including)

References