ambariGHSA-9q6v-rxmw-g3gh
Apache Ambari: Various Cross site scripting problems
Medium6.1CVE-2023-50378 · Published Mar 1, 2024 · updated Oct 3, 2024
Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.ambari:ambari Maven | < 2.7.8 | 2.7.8 |
Details and references
More ambari advisories
All ambari| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 122023 | Apache Ambari Expression Language Injection vulnerability | High8.8 | 2.7.7 |
| Jul 122023 | Apache Ambari Expression Language Injection vulnerability | High8.8 | 2.7.7 |
| May 172022 | Apache Ambari SSRF Vulnerability | Medium | 2.1.0 |
| May 172022 | Apache Ambari Open Redirect | Medium | 2.1.2 |
| May 172022 | Apache Ambari reveals administrator passwords | Medium5.5 | 2.4.0 |
| May 172022 | Apache Ambari Improper Access Control | Critical9.8 | 2.4.2 |