CVE-2014-3582

I

n Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:08

Type Values Removed Values Added
References () https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.4.0 - Issue Tracking, Third Party Advisory () https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.4.0 - Issue Tracking, Third Party Advisory

Information

Published : 2017-03-29 20:59

Updated : 2025-04-20 01:37


NVD link : CVE-2014-3582

Mitre link : CVE-2014-3582

CVE.ORG link : CVE-2014-3582


JSON object : View

Products Affected
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')