CVE-2020-13924: Apache Ambari

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.

Affected products

  • Apache Ambari: up to and including 2.6.2.2

Published 2021-03-17. Last modified 2026-06-17.