Lucene search

K
githubGitHub Advisory DatabaseGHSA-RGHC-9FHX-H32M
HistoryFeb 27, 2024 - 9:31 a.m.

Apache Ambari: authenticated users could perform command injection to perform RCE

2024-02-2709:31:16
CWE-94
GitHub Advisory Database
github.com
5
apache ambari
command injection
rce
upgrade
cluster operator

7.7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Malicious code injection in Apache Ambari in prior to 2.7.8.Β Users are recommended to upgrade to version 2.7.8, which fixes this issue.

Impact:
A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.

Affected configurations

Vulners
Node
padrinocontribRange<2.7.8

7.7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for GHSA-RGHC-9FHX-H32M