PT-2024-2027 · Apache · Apache Ambari

·

CVE-2023-50378

·

Published

2024-03-01

·

Updated

2025-05-28

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Ambari versions prior to 2.7.8
Description The issue is related to a lack of proper input validation and constraint enforcement, which could be exploited to perform unauthorized actions, including data access, session hijacking, and delivering malicious payloads. This is a stored XSS issue, where malicious code gets executed whenever a legitimate user interacts with the compromised part of Ambari.
Recommendations For Apache Ambari versions prior to 2.7.8, upgrade to version 2.7.8, which fixes this issue. As a temporary workaround, consider restricting access to potentially vulnerable components of Ambari to minimize the risk of exploitation.

Exploit

Fix

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01892
CVE-2023-50378
GHSA-9Q6V-RXMW-G3GH

Affected Products

Apache Ambari