First published: Mon Nov 02 2015(Updated: )
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ambari | <=2.1.1 | |
Apache Ambari | =1.7.0 | |
Apache Ambari | =2.0.0 | |
Apache Ambari | =2.0.1 | |
Apache Ambari | =2.0.2 | |
Apache Ambari | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5210 is classified as a medium severity vulnerability due to its potential for exploitation through phishing attacks.
To fix CVE-2015-5210, upgrade Apache Ambari to version 2.1.2 or later.
CVE-2015-5210 allows remote attackers to redirect users to malicious websites, posing significant phishing risks.
Apache Ambari versions before 2.1.2, as well as versions 1.7.0, 2.0.0, 2.0.1, 2.0.2, and 2.1.0 are affected by CVE-2015-5210.
CVE-2015-5210 is an open redirect vulnerability that enables attackers to redirect users to arbitrary external sites.