Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ambari | Apache | 1.5.0 (including) | 1.5.0 (including) |
Ambari | Apache | 1.5.1 (including) | 1.5.1 (including) |
Ambari | Apache | 1.6.0 (including) | 1.6.0 (including) |
Ambari | Apache | 1.6.1 (including) | 1.6.1 (including) |
Ambari | Apache | 1.7.0 (including) | 1.7.0 (including) |
Ambari | Apache | 2.0.0 (including) | 2.0.0 (including) |
Ambari | Apache | 2.0.1 (including) | 2.0.1 (including) |
Ambari | Apache | 2.0.2 (including) | 2.0.2 (including) |