CVE-2015-1775: Apache Ambari

Medium severity, CVSS 5.5. EPSS: 3% chance of exploitation in the next 30 days.

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

Affected products

  • Apache Ambari: version 1.5.0 only; version 1.5.1 only; version 1.6.0 only; version 1.6.1 only; version 1.7.0 only; version 2.0.0 only; …

Published 2015-11-02. Last modified 2026-06-17.