PT-2024-2027 · Apache · Apache Ambari

Brahma Reddy Battula

·

Published

2024-03-01

·

Updated

2025-05-28

·

CVE-2023-50378

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Ambari versions prior to 2.7.8
Description The issue is related to a lack of proper input validation and constraint enforcement, which could be exploited to perform unauthorized actions, including data access, session hijacking, and delivering malicious payloads. This is a stored XSS issue, where malicious code gets executed whenever a legitimate user interacts with the compromised part of Ambari.
Recommendations For Apache Ambari versions prior to 2.7.8, upgrade to version 2.7.8, which fixes this issue. As a temporary workaround, consider restricting access to potentially vulnerable components of Ambari to minimize the risk of exploitation.

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-01892
CVE-2023-50378
GHSA-9Q6V-RXMW-G3GH

Affected Products

Apache Ambari