CVE-2015-3186
EUVD-2015-325602.11.2015, 19:59
Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | ambari | 𝑥 ≤ 2.0.2 |
| apache | ambari | 1.7.0 |
| apache | ambari | 2.0.0 |
| apache | ambari | 2.0.1 |
𝑥
= Vulnerable software versions