Description
SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
Remediation
References
https://lists.apache.org/thread/302c4hwfjy9lx63jrbhcdx948pxc54l1
Related Vulnerabilities
CVE-2018-17246 Vulnerability in npm package kibana
CVE-2019-10080 Vulnerability in maven package org.apache.nifi:nifi-lookup-services-bundle
CVE-2016-3081 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2023-26048 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2019-10301 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-plugin