CVE-2023-50379
published 2024-02-27CVE-2023-50379: Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.06%
60.9th percentile
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ambari | < 2.7.8 | 2.7.8 |
| apache_software_foundation | apache_ambari | 2.7.0 – 2.7.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Ambari: authenticated users could perform command injection to perform RCE
osv·2024-02-27
CVE-2023-50379 [HIGH] Apache Ambari: authenticated users could perform command injection to perform RCE
Apache Ambari: authenticated users could perform command injection to perform RCE
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
GHSA
Apache Ambari: authenticated users could perform command injection to perform RCE
ghsa·2024-02-27
CVE-2023-50379 [HIGH] CWE-94 Apache Ambari: authenticated users could perform command injection to perform RCE
Apache Ambari: authenticated users could perform command injection to perform RCE
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-27
Published