Apache Ambari server side Request Forgery Vulnerability (CVE-2015-1775)
Apache Ambari server side Request Forgery Vulnerability (CVE-2015-1775)
Release date:
Updated on:
Affected Systems:
Apache Group Ambari <2.1.0
Description:
CVE (CAN) ID: CVE-2015-1775
Apache Ambari is a tool that defines, manages, and monitors Apache Hadoop clusters.
In Apache Ambari versions earlier than 2.1.0, the proxy endpoint (api/v1/proxy) has the server-side Request Forgery Vulnerability. authenticated remote users use constructed REST calls, this vulnerability allows you to perform port scans and access insecure services.
<* Source: Mateusz Olejarka (SecuRing)
Link: https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities
Use Ambari to install Hadoop clusters in CentOS 6.5
This article permanently updates the link address: