PT-2015-5439 · Apache · Apache Ambari

Mateusz Olejarka

·

Published

2015-11-02

·

Updated

2022-05-17

·

CVE-2015-1775

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Ambari versions prior to 2.1.0
Description A server-side request forgery (SSRF) issue exists in the proxy endpoint "api/v1/proxy" that allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "api/v1/proxy" endpoint to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1775
GHSA-9G2J-5685-H44H

Affected Products

Apache Ambari