CVE-2017-5655

EUVD-2017-14737
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
apacheambari
2.2.2
apacheambari
2.2.2:rc0
apacheambari
2.2.2:rc1
apacheambari
2.4.0
apacheambari
2.4.0:rc0
apacheambari
2.4.1
apacheambari
2.4.1:rc0
apacheambari
2.4.1:rc1
apacheambari
2.4.2
apacheambari
2.4.2:rc0
apacheambari
2.4.2:rc1
apacheambari
2.5.0
apacheambari
2.5.0:rc0
apacheambari
2.5.0:rc1
apacheambari
2.5.0:rc2
𝑥
= Vulnerable software versions