CVE-2014-3582: Apache Ambari

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.

Affected products

  • Apache Ambari: up to and including 2.2.2

Published 2017-03-29. Last modified 2026-06-17.