Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Ambari 跨站请求伪造漏洞
Vulnerability Description
Apache Ambari是美国阿帕奇(Apache)软件基金会的一套配置、管理和监控Apache Hadoop集群的工具。该工具支持作业与任务执行的可视化和分析、支持系统报警等。 Apache Ambari 2.1.0之前版本的proxy endpoint(api/v1/proxy)中存在跨站请求伪造漏洞。远程攻击者可借助特制的REST调用利用该漏洞执行端口扫描,访问不安全的服务。
CVSS Information
N/A
Vulnerability Type
N/A