CVE-2020-13924: Path Traversal
Published Mar 17, 2021
·Updated
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
Affected Software
1 affected component
Apache Ambari<=2.6.2.2
Event History
Mar 17, 2021
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-13924?
CVE-2020-13924 is a vulnerability in Apache Ambari versions 2.6.2.2 and earlier that allows malicious users to construct file names for directory traversal and traverse to other directories to download files.
2
How severe is CVE-2020-13924?
CVE-2020-13924 has a severity score of 7.5, classified as high.
3
What is the affected software by CVE-2020-13924?
Apache Ambari versions 2.6.2.2 and earlier are affected by CVE-2020-13924.
4
How can malicious users exploit CVE-2020-13924?
Malicious users can exploit CVE-2020-13924 by constructing file names for directory traversal and accessing files in other directories.
5
Is there a fix for CVE-2020-13924?
To fix CVE-2020-13924, update Apache Ambari to a version later than 2.6.2.2.