Details
-
Bug
-
Status: Resolved
-
Blocker
-
Resolution: Fixed
-
2.7.1
Description
Remove dependency on JQuery 1.8.0 for Ambari Server UI due to security concerns. See
- CVE-2012-6708 - https://nvd.nist.gov/vuln/detail/CVE-2012-6708
- CVE-2011-4969 - https://nvd.nist.gov/vuln/detail/CVE-2011-4969
- CVE-2015-9251 - https://nvd.nist.gov/vuln/detail/CVE-2015-9251
It is recommended that JQuery is updated to 1.8.3+1
Path to offending file:
ambari |- ambari-server-2.7.1.0-119.x86_64.rpm | |- usr | | |- lib | | | |- ambari-server | | | | |- web | | | | | |- api-docs | | | | | | |- lib | | | | | | | |- jquery-1.8.0.min.js