Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8
Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads.
Users are recommended to upgrade to version 2.7.8 which fixes this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 03 Oct 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 | |
References |
|
Thu, 03 Oct 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 03 Oct 2024 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue. | Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue. |
Weaknesses | CWE-79 |
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-03-01T14:38:29.732Z
Updated: 2024-11-07T16:03:03.744Z
Reserved: 2023-12-07T14:02:23.087Z
Link: CVE-2023-50378
Vulnrichment
Updated: 2024-08-02T22:16:46.837Z
NVD
Status : Awaiting Analysis
Published: 2024-03-01T15:15:08.310
Modified: 2024-11-07T16:35:10.320
Link: CVE-2023-50378
Redhat
No data.