Description
SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2109 | SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. |
Github GHSA |
GHSA-p7w2-784m-qpq9 | Apache Ambari Expression Language Injection vulnerability |
References
History
Fri, 04 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-10-04T13:50:54.277Z
Reserved: 2022-11-23T09:10:46.930Z
Link: CVE-2022-45855
Updated: 2024-08-03T14:24:02.941Z
Status : Modified
Published: 2023-07-12T10:15:09.547
Modified: 2026-06-17T05:10:52.290
Link: CVE-2022-45855
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
EUVD
Github GHSA