Ambari
Vendor:
First CVE: Nov 2, 2015 · Active for 10 years
26
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ambari over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2015
10 years ago
Most Recent CVE
Jan 21, 2025
549 days ago
CVE Severity & Scoring
Ambari26 CVEs
12%
42%
35%
12%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (7.7%)
Network18 (69.2%)
Unknown6 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (73.1%)
High1 (3.8%)
Unknown6 (23.1%)
User Interaction
None18 (69.2%)
Unknown6 (23.1%)
Required2 (7.7%)
Privileges Required
Low9 (34.6%)
High1 (3.8%)
None10 (38.5%)
Unknown6 (23.1%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6807CRITICAL Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying syste | Mar 28, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-5642CRITICAL During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. | Apr 3, 2017 | 9.8 | 30 | NO | NO |
CVE-2014-3582CRITICAL In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster. | Mar 29, 2017 | 9.8 | 30 | NO | NO |
CVE-2023-50379HIGH Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cluster Operator can manipulate t | Feb 27, 2024 | 8.8 | 28 | NO | NO |
CVE-2022-42009HIGH SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to up | Jul 12, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-23196HIGH A code injection vulnerability exists in the Ambari Alert Definition
feature, allowing authenticated users to inject and execute arbitrary
shell commands. The vulnerability arise | Jan 21, 2025 | 8.8 | 26 | NO | NO |
CVE-2022-45855HIGH SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to | Jul 12, 2023 | 8.8 | 26 | NO | NO |
CVE-2018-8042HIGH Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled fo | Jul 18, 2018 | 8.1 | 26 | NO | NO |
CVE-2024-51941HIGH A remote code injection vulnerability exists in the Ambari Metrics and
AMS Alerts feature, allowing authenticated users to inject and execute
arbitrary code. The vulnerability oc | Jan 21, 2025 | 8.8 | 25 | NO | NO |
CVE-2017-5654HIGH In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari serve | May 12, 2017 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Ambari
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5.0 | 2 | 6.7 | 2.1% | 0 | 0 |
| 2.4.2 | 2 | 7.3 | 2.0% | 0 | 0 |
| 2.4.1 | 4 | 7.8 | 2.1% | 0 | 0 |
| 2.4.0 | 4 | 8.0 | 2.1% | 0 | 0 |
| 2.2.2 | 2 | 6.3 | 1.7% | 0 | 0 |
| 2.2.1 | 1 | 5.5 | 0.5% | 0 | 0 |
| 2.2.0 | 1 | 5.5 | 0.5% | 0 | 0 |
| 2.1.2 | 1 | 5.5 | 0.5% | 0 | 0 |
| 2.1.1 | 1 | 5.5 | 0.5% | 0 | 0 |
| 2.1.0 | 3 | 5.9 | 2.5% | 0 | 0 |
| 2.0.2 | 3 | 5.6 | 2.5% | 0 | 0 |
| 2.0.1 | 5 | 5.4 | 2.5% | 0 | 0 |
| 2.0.0 | 5 | 5.4 | 2.5% | 0 | 0 |
| 1.7.0 | 4 | 5.3 | 3.0% | 0 | 0 |
| 1.6.1 | 1 | 5.5 | 2.9% | 0 | 0 |
| 1.6.0 | 1 | 5.5 | 2.9% | 0 | 0 |
| 1.5.1 | 1 | 5.5 | 2.9% | 0 | 0 |
| 1.5.0 | 1 | 5.5 | 2.9% | 0 | 0 |