GHSA-rghc-9fhx-h32m
Dashboard / Vulnerabilities / GHSA-rghc-9fhx-h32m
Summary: Apache Ambari: authenticated users could perform command injection to perform RCE
Details: Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-50379, https://github.com/apache/ambari, https://lists.apache.org/thread/jglww6h6ngxpo1r6r5fx7ff7z29lnvv8, http://www.openwall.com/lists/oss-security/2024/02/27/1
Affected packages
Package
Name: org.apache.ambari.contrib.views:ambari-contrib-views
Purl: pkg:maven/org.apache.ambari.contrib.views/ambari-contrib-views
Affected ranges
Type: ECOSYSTEM
Events:
