Description
SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
Remediation
References
https://lists.apache.org/thread/6xf477ttz1oxmg0bx0tpdoz2mlqd7sbc
Related Vulnerabilities
CVE-2022-28153 Vulnerability in maven package org.jvnet.hudson.plugins:sitemonitor
CVE-2023-46233 Vulnerability in maven package org.webjars.npm:github-com-brix-crypto-js
CVE-2023-34464 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-28158 Vulnerability in maven package org.apache.archiva:archiva-web-common
CVE-2022-28731 Vulnerability in maven package org.apache.jspwiki:jspwiki-war