Lucene search

K
cvelistApacheCVELIST:CVE-2023-50378
HistoryMar 01, 2024 - 2:38 p.m.

CVE-2023-50378 Apache Ambari: Various XSS problems

2024-03-0114:38:29
CWE-20
apache
www.cve.org
apache ambari
xss
vulnerability
upgrade
version 2.7.8

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8

Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads.

Users are recommended to upgrade to version 2.7.8 which fixes this issue.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Ambari",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "2.7.7",
        "status": "affected",
        "version": "2.7.0",
        "versionType": "semver"
      }
    ]
  }
]

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for CVELIST:CVE-2023-50378