AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-8003

MEDIUM · CVSS 5.3 EPSS 4.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-05-03 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. It affects Apache. Exploitation may require the attacker to be authenticated.

CVE
CVE-2018-8003
Severity
MEDIUM
CVSS
5.3
EPSS
4.40%
Apache

Original NVD Description

Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host the Ambari Server runs on that is accessible by the user the Ambari Server is running as. Direct network access to the Ambari Server is required to issue this request, and those Ambari Servers that are protected behind a firewall, or in a restricted network zone are at less risk of being affected by this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)