{"id":"CVE-2017-5642","details":"During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.","modified":"2026-07-08T12:27:58.971838Z","published":"2017-04-03T16:59:00.163Z","references":[{"type":"ADVISORY","url":"https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.5.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/ambari","events":[{"introduced":"3689a8db02a2dbb7814490a0aba20e7de3771c0e"},{"last_affected":"3b9056bac4324ba929a72985a80b99e7e85931a6"}],"database_specific":{"extracted_events":[{"introduced":"2.4.0"},{"last_affected":"2.4.0"},{"introduced":"2.4.1"},{"last_affected":"2.4.1"},{"introduced":"2.4.2"},{"last_affected":"2.4.2"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:apache:ambari:2.4.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:ambari:2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:ambari:2.4.2:*:*:*:*:*:*:*"]}}],"versions":["2.4.0","2.4.1","2.4.2","release-2.4.2-rc1","release-2.4.2","release-2.4.2-rc0","release-2.4.1-rc1","release-2.4.1","release-2.4.1-rc0","release-2.4.0-rc0","release-2.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5642.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}