1
I Use This!
Moderate Activity
Analyzed about 9 hours ago. based on code collected about 9 hours ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2025-23196 BDSA-2025-0646 Jan 21, 2025 A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell comm more...
2.7.1, 2.7.0, 2.6.2, 2.6.1, 2.6.0, 2.5.2, 2.5.1, 2.4.3, 2.5.0, 2.4.2
CVE-2025-23195 BDSA-2025-0667 Jan 21, 2025 An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerabil more...
2.7.1, 2.7.0, 2.6.2, 2.6.1, 2.6.0, 2.5.2, 2.5.1, 2.4.3, 2.5.0, 2.4.2
CVE-2024-51941 BDSA-2025-0648 Jan 21, 2025 A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitra more...
2.7.1, 2.7.0, 2.6.2, 2.6.1, 2.6.0, 2.5.2, 2.5.1, 2.4.3, 2.5.0, 2.4.2
CVE-2023-50380 BDSA-2024-1923 Medium Feb 27, 2024 XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Deta more...
2.7.1, 2.7.0
CVE-2023-50379 BDSA-2024-1922 Feb 27, 2024 Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Clus more...
2.7.1, 2.7.0, 2.6.2, 2.6.1, 2.6.0, 2.5.2, 2.5.1, 2.4.3, 2.5.0, 2.4.2
CVE-2023-50378 BDSA-2024-1938 Mar 01, 2024 Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited to more...
2.7.1, 2.7.0
CVE-2022-45855 BDSA-2023-1767 High Jul 12, 2023 SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remote more...
2.7.1, 2.7.0
CVE-2022-42009 BDSA-2023-1766 High Jul 12, 2023 SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely more...
2.7.1, 2.7.0
CVE-2020-1936 BDSA-2021-0506 Medium Mar 02, 2021 A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
2.7.1, 2.7.0, 2.6.2, 2.6.1, 2.6.0, 2.5.2, 2.5.1, 2.4.3, 2.5.0, 2.4.2
BDSA-2021-0682 Medium Mar 17, 2021 Apache Ambari contains a directory traversal vulnerability. This could allow a user to download files from directories they do not have permission to a more...