CVE-2017-5655
CVE-2017-5655
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 May 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.
Affected products
Apache Software Foundation · Apache AmbariWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →