Malicious Code Injection in Apache Ambari Prior to 2.7.8
CVE-2023-50379

8.8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
27 February 2024

Summary

A vulnerability in Apache Ambari allows a Cluster Operator to perform malicious code injection in versions prior to 2.7.8. By manipulating requests, an attacker could potentially gain root access to the cluster's main host, compromising the integrity and security of the system. It is highly recommended for users to upgrade to version 2.7.8 or later to address this security issue. Ensure your systems are secure by maintaining updated software and applying necessary patches.

Affected Version(s)

Apache Ambari 2.7.0 <= 2.7.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.