CVE-2015-3186
02.11.2015, 19:59
Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.
Vendor | Product | Version |
---|---|---|
apache | ambari | 𝑥 ≤ 2.0.2 |
apache | ambari | 1.7.0 |
apache | ambari | 2.0.0 |
apache | ambari | 2.0.1 |
𝑥
= Vulnerable software versions