QID 375562

Date Published: 2021-05-13

QID 375562: Apache Ambari Cross-Site Scripting Vulnerability

Apache Ambari is a software project of the Apache Software Foundation. Ambari enables system administrators to provision, manage and monitor a Hadoop cluster, and also to integrate Hadoop with the existing enterprise infrastructure.

A cross-site scripting issue was found in Apache Ambari Views.

Affected Version:
Apache Ambari prior to 2.7.4

QID Detection Logic:(Authenticated)
This QID checks if vulnerable version of Apache Ambari is running or not by checking "/var/lib/ambari-server/resources/version"

Successful exploitation could lead to integrity issue.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to update Apache Ambari to 2.7.4.

    CVEs related to QID 375562

    Software Advisories
    Advisory ID Software Component Link
    Apache Ambari 2.7.4 URL Logo ambari.apache.org/