CVE-2017-5654
CVE-2017-5654
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 May 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
Affected products
Apache Software Foundation · Apache AmbariWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →