CVE-2017-5654: Apache Ambari
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
Affected products
- Apache Ambari: version 2.4.0 only; version 2.4.1 only; version 2.5.0 only
Published 2017-05-12. Last modified 2026-06-17.