CVE-2023-50379
published 2024-02-27CVE-2023-50379: Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster…
high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ambari | < 2.7.8 | 2.7.8 |
| apache_software_foundation | apache_ambari | 2.7.0 – 2.7.7 | — |