CVE-2014-3582

CWE-94Code Injection3 documents3 sources
Severity
9.8CRITICAL
EPSS
0.3%
top 43.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 29
Latest updateMay 17

Description

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDapache/ambari2.2.2

🔴Vulnerability Details

2
GHSA
GHSA-4wh4-4qwc-3jqg: In Ambari 12022-05-17
CVEList
CVE-2014-3582: In Ambari 12017-03-29