QID 994848
Date Published: 2023-08-17
QID 994848: Java (Maven) Security Update for org.apache.ambari:ambari (GHSA-9g2j-5685-h44h)
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9g2j-5685-h44h for updates and patch information.
Vendor References
- GHSA-9g2j-5685-h44h -
github.com/advisories/GHSA-9g2j-5685-h44h
CVEs related to QID 994848
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9g2j-5685-h44h | org.apache.ambari:ambari |
|