CVE-2017-5655

In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
apacheambari
2.2.2
apacheambari
2.2.2:rc0
apacheambari
2.2.2:rc1
apacheambari
2.4.0
apacheambari
2.4.0:rc0
apacheambari
2.4.1
apacheambari
2.4.1:rc0
apacheambari
2.4.1:rc1
apacheambari
2.4.2
apacheambari
2.4.2:rc0
apacheambari
2.4.2:rc1
apacheambari
2.5.0
apacheambari
2.5.0:rc0
apacheambari
2.5.0:rc1
apacheambari
2.5.0:rc2
𝑥
= Vulnerable software versions