Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/02/27/1 | Third Party Advisory Mailing List |
| https://lists.apache.org/thread/jglww6h6ngxpo1r6r5fx7ff7z29lnvv8 | Vendor Advisory Mailing List |
| http://www.openwall.com/lists/oss-security/2024/02/27/1 | Third Party Advisory Mailing List |
| https://lists.apache.org/thread/jglww6h6ngxpo1r6r5fx7ff7z29lnvv8 | Vendor Advisory Mailing List |
Configurations
History
No history.
Information
Published : 2024-02-27 09:15
Updated : 2025-05-05 21:01
NVD link : CVE-2023-50379
Mitre link : CVE-2023-50379
CVE.ORG link : CVE-2023-50379
JSON object : View
Products Affected
apache
- ambari
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
