CVE-2016-4976: Infoleak
Published Mar 29, 2017
·Updated
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
Affected Software
10 affected componentsFixes available
Apache Ambari=2.0.0
Apache Ambari=2.0.1
Apache Ambari=2.0.2
Apache Ambari=2.1.0
Apache Ambari=2.1.1
Apache Ambari=2.1.2
Apache Ambari=2.2.0
Apache Ambari=2.2.1
Apache Ambari=2.2.2
maven/org.apache.ambari:ambari>=2.0.0<2.4.0
2.4.0
Event History
Mar 29, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 17, 2022
Advisory Published
02:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-4976?
CVE-2016-4976 has been rated as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2016-4976?
To fix CVE-2016-4976, upgrade to Apache Ambari version 2.4.0 or later.
3
What kind of information can be exposed by CVE-2016-4976?
CVE-2016-4976 can expose KDC administrator passwords to local users via process listings.
4
Which versions of Apache Ambari are affected by CVE-2016-4976?
CVE-2016-4976 affects Apache Ambari versions 2.0.0 through 2.2.2.
5
Can local users exploit CVE-2016-4976?
Yes, local users can exploit CVE-2016-4976 to obtain sensitive KDC administrator passwords.