CVE-2015-1775
published 2015-11-02CVE-2015-1775: Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to…
PriorityP428medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
2.95%
85.7th percentile
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ambari | — | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Ambari SSRF Vulnerability
ghsa·2022-05-17
CVE-2015-1775 [MEDIUM] CWE-918 Apache Ambari SSRF Vulnerability
Apache Ambari SSRF Vulnerability
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (`api/v1/proxy`) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
OSV
Apache Ambari SSRF Vulnerability
osv·2022-05-17
CVE-2015-1775 [MEDIUM] Apache Ambari SSRF Vulnerability
Apache Ambari SSRF Vulnerability
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (`api/v1/proxy`) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5210 CVE-2015-3186 CVE-2015-3270 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2
bugzilla·2015-10-19·CVSS 5.5
CVE-2015-5210 [MEDIUM] CVE-2015-5210 CVE-2015-3186 CVE-2015-3270 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2
CVE-2015-5210 CVE-2015-3186 CVE-2015-3270 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2
Four flaws were reported in Apache Ambari:
CVE-2015-5210: Unvalidated Redirects and Forwards using targetURI parameter can enable phishing exploits
Versions Affected: 1.7.0 to 2.1.1
Versions Fixed: 2.1.2
Description: A redirect to an untrusted server is possible via unvalidated input that specifies a redirect URL upon
successful login.
CVE-2015-3186: Apache Ambari XSS vulnerability
Versions Affected: 1.7.0 to 2.0.2
Versions Fixed: 2.1.0
Description: Ambari allows authenticated cluster operator users to specify arbitrary text as a note when saving
configuration changes. This note field is rendered as is (unescaped HTML). This exposes opportunities for XSS.
CVE-2015-3270: A non-administra
Bugzilla
CVE-2015-3186 CVE-2015-3270 CVE-2015-5210 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2 [fedora-all]
bugzilla·2015-10-19·CVSS 5.5
CVE-2015-3186 [MEDIUM] CVE-2015-3186 CVE-2015-3270 CVE-2015-5210 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2 [fedora-all]
CVE-2015-3186 CVE-2015-3270 CVE-2015-5210 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
2015-11-02
Published