{"id":"CVE-2016-0731","details":"The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.","modified":"2026-07-08T12:36:14.384583Z","published":"2016-05-18T14:59:03.007Z","references":[{"type":"WEB","url":"https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.0/bk_releasenotes_ambari_2.2.1.0/content/ambari_relnotes-2.2.1.0-cves.html"},{"type":"ADVISORY","url":"https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.2.1"},{"type":"ADVISORY","url":"https://issues.apache.org/jira/browse/AMBARI-14780"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/ambari","events":[{"introduced":"0"},{"last_affected":"c1d56c3bf43bb9bd10e4cf14f4720049f7697fec"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.2.0"}]}}],"versions":["release-2.2.0-rc1","release-2.2.0","release-2.2.0-rc0","2.1.3_to_2.2.0_rename","Ambari-2.1.0-tag","release-2.1.0-rc1","release-2.1.0","release-2.1.0-rc0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0731.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}