Description
SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2109 | SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7. |
Github GHSA |
GHSA-p7w2-784m-qpq9 | Apache Ambari Expression Language Injection vulnerability |
References
History
Fri, 04 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-10-04T13:50:54.277Z
Reserved: 2022-11-23T09:10:46.930Z
Link: CVE-2022-45855
Updated: 2024-08-03T14:24:02.941Z
Status : Modified
Published: 2023-07-12T10:15:09.547
Modified: 2024-11-21T07:29:50.737
Link: CVE-2022-45855
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA