Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.
CVE-2022-42009

8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
12 July 2023

Summary

The SpringEL injection vulnerability in Apache Ambari allows an authenticated malicious user to execute arbitrary code on the server. This weakness affects versions 2.7.0 through 2.7.6 of Apache Ambari, potentially compromising the integrity and confidentiality of the system. Users are strongly advised to upgrade to version 2.7.7 to mitigate this risk.

Affected Version(s)

Apache Ambari 2.7.0 <= 2.7.6

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

.