CVE-2017-5655
Published May 15, 2017
Last updated 7 years ago
Overview
- Description
- In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.
- Source
- security@apache.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:ambari:2.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40ED1582-73DA-4CFE-9B2A-765A464FB205" }, { "criteria": "cpe:2.3:a:apache:ambari:2.2.2:rc0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6EA965D-7D10-4C4E-A4A7-762538BDFEB0" }, { "criteria": "cpe:2.3:a:apache:ambari:2.2.2:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37DCE19A-294D-4384-92CB-42B36F759F82" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "243741C6-FCA5-4E8F-93A6-033144214F31" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.0:rc0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8185C0EB-4BF3-41EF-AD85-3A7AFFFAD9F3" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "114B2179-C5A7-4802-9A3C-580BF8153285" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.1:rc0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9046DB2D-E7DF-434C-BE67-759BD85E0B08" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.1:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9ECC970E-2645-4B03-9E28-16359C5022BF" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9668FD5A-C08E-403B-8B6F-04FFA3C6296D" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.2:rc0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "699F0806-D841-4955-A101-448E3DC62E8E" }, { "criteria": "cpe:2.3:a:apache:ambari:2.4.2:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27C40CB9-5E15-481F-9519-01820C348039" }, { "criteria": "cpe:2.3:a:apache:ambari:2.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C282AEEA-8E12-4B62-8535-B23EFFA0D188" }, { "criteria": "cpe:2.3:a:apache:ambari:2.5.0:rc0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7DA49EF4-F633-401D-AE87-569E85ABC0FE" }, { "criteria": "cpe:2.3:a:apache:ambari:2.5.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CBBC4A8-AD6B-4B9D-ADAB-2DD436993260" }, { "criteria": "cpe:2.3:a:apache:ambari:2.5.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DCBCECF-6079-4330-8BB2-CAD56B938997" } ], "operator": "OR" } ] } ]