Malicious code injection in Apache Ambari in prior to 2.7.8.Β Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact:
A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
CPE | Name | Operator | Version |
---|---|---|---|
org.apache.ambari.contrib.views:ambari-contrib-views | lt | 2.7.8 |