The File Browser View in Apache Ambari prior to 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.
apache ambari