CVE-2017-5642: Critical severity Apache Ambari vulnerability
Published Apr 3, 2017
·Updated
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
Affected Software
3 affected components
Apache Ambari=2.4.0
Apache Ambari=2.4.1
Apache Ambari=2.4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
After installing Ambari 2.4.0 through 2.4.2, ensure Ambari Server artifacts are created/set with proper ACLs.
Ambari Server artifact ACLs = proper ACLs (as required)
Event History
Apr 3, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5642?
CVE-2017-5642 has a medium severity rating due to improper ACLs during installation.
2
How do I fix CVE-2017-5642?
To fix CVE-2017-5642, upgrade to Apache Ambari version 2.5.0 or later.
3
What are the affected versions for CVE-2017-5642?
The affected versions for CVE-2017-5642 are Apache Ambari 2.4.0, 2.4.1, and 2.4.2.
4
What components are impacted by CVE-2017-5642?
CVE-2017-5642 impacts the Ambari Server artifacts due to improper access control lists.
5
Is there a public exploit for CVE-2017-5642?
There is no known public exploit specifically for CVE-2017-5642 at this time.