High severity7.5NVD Advisory· Published Mar 17, 2021· Updated Jun 17, 2026
CVE-2020-13924
CVE-2020-13924
Description
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
Affected products
3- Apache Software Foundation/Apache Ambariv5Range: Apache Ambari
Patches
Vulnerability mechanics
References
1- mail-archives.apache.org/mod_mbox/ambari-user/202102.mbox/%3CCAEJYuxEQZ_aPwJdAaSxPu-Dva%3Dhc7zZUx3-pzBORbd23g%2BGH1A%40mail.gmail.com%3EnvdExploitMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.