Fedora Account System
Red Hat Associate
Red Hat Customer
Multiple security vulnerabilities were found in Ambari. CVE-2017-5654: XML injection vulnerability in Hive View An authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Amari server executes. Access to files are limit to the set of files for which the user that executes the Ambari server has read access. CVE-2017-5655: Possible exposure of sensitive data in files created in Ambari temp directory when downloading configurations Sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host. External References: https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.5.1
Created ambari tracking bugs for this issue: Affects: fedora-all [bug 1451406]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.