SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
References
Link Resource
https://lists.apache.org/thread/6xf477ttz1oxmg0bx0tpdoz2mlqd7sbc Mailing List Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2023-07-12T09:58:19.752Z

Updated: 2023-07-12T09:58:19.752Z

Reserved: 2022-10-02T08:56:54.293Z


Link: CVE-2022-42009

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-12T10:15:09.447

Modified: 2023-07-20T01:22:32.963


Link: CVE-2022-42009

JSON object: View

cve-icon Redhat Information

No data.

CWE