Логотип exploitDog
bind:CVE-2023-50380
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-50380

Количество 3

Количество 3

nvd логотип

CVE-2023-50380

почти 2 года назад

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from low-privilege users. The vulnerability was caused through lack of proper user input validation. This vulnerability is known as an XML External Entity (XXE) injection attack. Attackers can exploit XXE vulnerabilities to read arbitrary files on the server, including sensitive system files. In theory, it might be possible to use this to escalate privileges.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qrp9-23p7-g5mf

почти 2 года назад

Apache Ambari XML External Entity injection

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-05024

почти 2 года назад

Уязвимость компонента Oozie Workflow Scheduler программного средства Apache Ambari, позволяющая нарушителю проводить XXE-атаки

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-50380

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from low-privilege users. The vulnerability was caused through lack of proper user input validation. This vulnerability is known as an XML External Entity (XXE) injection attack. Attackers can exploit XXE vulnerabilities to read arbitrary files on the server, including sensitive system files. In theory, it might be possible to use this to escalate privileges.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-qrp9-23p7-g5mf

Apache Ambari XML External Entity injection

CVSS3: 6.5
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-05024

Уязвимость компонента Oozie Workflow Scheduler программного средства Apache Ambari, позволяющая нарушителю проводить XXE-атаки

CVSS3: 5.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу