PT-2015-5439 · Apache · Apache Ambari

Mateusz Olejarka

·

Publicado

2015-11-02

·

Atualizado

2022-05-17

·

CVE-2015-1775

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Ambari versions prior to 2.1.0
Description A server-side request forgery (SSRF) issue exists in the proxy endpoint "api/v1/proxy" that allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "api/v1/proxy" endpoint to minimize the risk of exploitation.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-1775
GHSA-9G2J-5685-H44H

Produtos afetados

Apache Ambari