PT-2021-2448 · Apache · Apache Ambari
Published
2021-03-01
·
Updated
2022-01-06
·
CVE-2020-1936
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Ambari versions prior to 2.7.4
Description:
A cross-site scripting issue was found in Apache Ambari Views. This issue may allow a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations:
For versions prior to 2.7.4, update to Apache Ambari 2.7.4 to resolve the issue. As a temporary workaround, consider restricting access to Apache Ambari Views until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Ambari