Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.
CVE-2022-42009
8HIGH
Summary
The SpringEL injection vulnerability in Apache Ambari allows an authenticated malicious user to execute arbitrary code on the server. This weakness affects versions 2.7.0 through 2.7.6 of Apache Ambari, potentially compromising the integrity and confidentiality of the system. Users are strongly advised to upgrade to version 2.7.7 to mitigate this risk.
Affected Version(s)
Apache Ambari 2.7.0 <= 2.7.6
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jecki Go ([email protected])