CVE-2022-42009

CWE-9174 documents4 sources
Severity
8.8HIGH
EPSS
0.2%
top 56.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12

Description

SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages3 packages

NVDapache/ambari2.7.02.7.7
Mavenorg.apache.ambari:ambari2.7.02.7.7
CVEListV5apache_software_foundation/apache_ambari2.7.02.7.6

🔴Vulnerability Details

3
GHSA
Apache Ambari Expression Language Injection vulnerability2023-07-12
OSV
Apache Ambari Expression Language Injection vulnerability2023-07-12
CVEList
Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.2023-07-12