CVE-2016-6807
Apache Ambari Improper Access Control
9.8
CRITICAL
CVSS 3.1
EPSS 2.4%
描述
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.
如何修補 CVE-2016-6807
要修補 CVE-2016-6807,請將受影響套件升級到下列已修補版本。
- —升級至 2.4.2 或更新版本
CVE-2016-6807 正在被利用嗎?
低 — EPSS 為 2.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 2.4.0, < 2.4.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |