Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j76q-99x2-v7vq

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache Ambari Improper Access Control

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.

Пакеты

Наименование

org.apache.ambari:ambari

maven
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.2

2.4.2

EPSS

Процентиль: 74%
0.00841
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
nvd
почти 9 лет назад

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.

EPSS

Процентиль: 74%
0.00841
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284