Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g359-p277-83p3

Опубликовано: 22 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. An attacker with authenticated access can exploit this vulnerability to execute arbitrary commands on the server. The issue has been fixed in the latest versions of Ambari.

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. An attacker with authenticated access can exploit this vulnerability to execute arbitrary commands on the server. The issue has been fixed in the latest versions of Ambari.

EPSS

Процентиль: 73%
0.00763
Низкий

8.8 High

CVSS3

Дефекты

CWE-75
CWE-77
CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. An attacker with authenticated access can exploit this vulnerability to execute arbitrary commands on the server. The issue has been fixed in the latest versions of Ambari.

EPSS

Процентиль: 73%
0.00763
Низкий

8.8 High

CVSS3

Дефекты

CWE-75
CWE-77
CWE-94