CVE-2015-3186
published 2015-11-02CVE-2015-3186: Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
2.33%
81.6th percentile
Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ambari | <= 2.0.2 | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
| apache | ambari | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5210 CVE-2015-3186 CVE-2015-3270 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2
bugzilla·2015-10-19·CVSS 5.5
CVE-2015-5210 [MEDIUM] CVE-2015-5210 CVE-2015-3186 CVE-2015-3270 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2
CVE-2015-5210 CVE-2015-3186 CVE-2015-3270 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2
Four flaws were reported in Apache Ambari:
CVE-2015-5210: Unvalidated Redirects and Forwards using targetURI parameter can enable phishing exploits
Versions Affected: 1.7.0 to 2.1.1
Versions Fixed: 2.1.2
Description: A redirect to an untrusted server is possible via unvalidated input that specifies a redirect URL upon
successful login.
CVE-2015-3186: Apache Ambari XSS vulnerability
Versions Affected: 1.7.0 to 2.0.2
Versions Fixed: 2.1.0
Description: Ambari allows authenticated cluster operator users to specify arbitrary text as a note when saving
configuration changes. This note field is rendered as is (unescaped HTML). This exposes opportunities for XSS.
CVE-2015-3270: A non-administra
Bugzilla
CVE-2015-3186 CVE-2015-3270 CVE-2015-5210 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2 [fedora-all]
bugzilla·2015-10-19·CVSS 5.5
CVE-2015-3186 [MEDIUM] CVE-2015-3186 CVE-2015-3270 CVE-2015-5210 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2 [fedora-all]
CVE-2015-3186 CVE-2015-3270 CVE-2015-5210 CVE-2015-1775 Apache Ambari: multiple flaws fixed in 2.1.2 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
2015-11-02
Published