CVE-2020-13924

HIGH

Apache Ambari < 2.6.2.2 - Path Traversal

Title source: llm
STIX 2.1

Description

In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0084
EPSS Percentile 74.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
apache/ambari < 2.6.2.2
Published Mar 17, 2021
Tracked Since Feb 18, 2026