Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrp9-23p7-g5mf

Опубликовано: 27 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Apache Ambari XML External Entity injection

XML External Entity injection in Apache Ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue.

More Details:

Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from low-privilege users. The vulnerability was caused through lack of proper user input validation.

This vulnerability is known as an XML External Entity (XXE) injection attack. Attackers can exploit XXE vulnerabilities to read arbitrary files on the server, including sensitive system files. In theory, it might be possible to use this to escalate privileges.

Пакеты

Наименование

org.apache.ambari.contrib.views:wfmanager

maven
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.8

2.7.8

EPSS

Процентиль: 34%
0.00137
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from low-privilege users. The vulnerability was caused through lack of proper user input validation. This vulnerability is known as an XML External Entity (XXE) injection attack. Attackers can exploit XXE vulnerabilities to read arbitrary files on the server, including sensitive system files. In theory, it might be possible to use this to escalate privileges.

CVSS3: 5.5
fstec
почти 2 года назад

Уязвимость компонента Oozie Workflow Scheduler программного средства Apache Ambari, позволяющая нарушителю проводить XXE-атаки

EPSS

Процентиль: 34%
0.00137
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611