CVE-2017-5654: High severity Apache Ambari vulnerability
Published May 12, 2017
·Updated
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
Affected Software
3 affected components
Apache Ambari=2.4.0
Apache Ambari=2.4.1
Apache Ambari=2.5.0
Event History
May 12, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-5654?
CVE-2017-5654 has a medium severity rating, indicating a moderate impact on system security.
2
How do I fix CVE-2017-5654?
To mitigate CVE-2017-5654, upgrade your Ambari installation to version 2.4.3 or 2.5.1 or later.
3
What software versions are affected by CVE-2017-5654?
CVE-2017-5654 affects Apache Ambari versions 2.4.0, 2.4.1, and 2.5.0.
4
What type of attack is possible due to CVE-2017-5654?
Due to CVE-2017-5654, an authorized user of Ambari Hive View may exploit the vulnerability to gain unauthorized read access to host files.
5
Who is vulnerable to CVE-2017-5654?
Any organization using Apache Ambari versions 2.4.0, 2.4.1, or 2.5.0 is vulnerable to CVE-2017-5654 if not updated.