PT-2025-4838 · Ambari · Ambari

Fcgboy

+4

·

Published

2025-01-21

·

Updated

2025-01-22

·

CVE-2025-23196

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ambari (affected versions not specified)
Description A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed using sh -c. An attacker with authenticated access can exploit this vulnerability to inject malicious commands, leading to remote code execution on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-23196

Affected Products

Ambari