cbcvebase.
CVE-2020-13924
published 2021-03-17

CVE-2020-13924: In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheambari<= 2.6.2.2
apache_software_foundationapache_ambariApache Ambari – 2.6.2.2